AI Chatbot Compliance: EU AI Act and US Chatbot Laws (2026)

What the EU AI Act, GDPR, HIPAA, the FTC Act, and US state chatbot laws require from a customer service chatbot, with the penalty for each and a five-step compliance checklist.

AI Chatbot Compliance: EU AI Act and US Chatbot Laws (2026)
Created by
Do not index
Created time
Apr 27, 2026 07:29 PM
AI chatbot compliance means meeting five duties: disclose the AI, offer a route to a person, sign the right data contracts, keep answers accurate, and keep records.
TL;DR
  • Article 50 of the EU AI Act has applied since 2 August 2026. A chatbot must tell people they are interacting with an AI system at the first interaction, unless that is obvious.
  • Breaking Article 50 can cost up to €15 million or 3% of worldwide annual turnover. The €35 million and 7% tier covers prohibited AI practices only.
  • California signed AB 1609 on 28 September 2026. It targets customer service chatbots by name and covers businesses with more than $500 million in gross annual revenue.
  • California SB 243 and Washington HB 2225 cover companion chatbots. Both exclude bots used only for customer service.
  • GDPR requires a signed data processing agreement (DPA) with the chatbot vendor. HIPAA requires a business associate agreement (BAA) before patient data enters a chat.
This guide is general information and is not legal advice.

Key takeaways

Law
Where it applies
What it asks of a customer service chatbot
Maximum penalty
EU AI Act, Article 50
Chatbots used by people in the EU
Tell people they are interacting with an AI system at the first interaction
€15 million or 3% of worldwide annual turnover
GDPR
Personal data of people in the EU
A lawful basis, a signed DPA with the vendor, and answers to access and erasure requests
€20 million or 4% of worldwide annual turnover
California AB 1609
Businesses with more than $500 million in gross annual revenue serving California customers
AI disclosure and a route to a human agent, from 1 January 2027
$5,000 for a first violation, $10,000 for each later one
Utah generative AI disclosure law
Consumer transactions in Utah
Say it is AI when a person clearly asks
$2,500 per violation
Summary graphic of five AI chatbot compliance duties: say it is AI, offer a person, sign the data contracts, keep answers accurate, and keep records
Summary graphic of five AI chatbot compliance duties: say it is AI, offer a person, sign the data contracts, keep answers accurate, and keep records

What is AI chatbot compliance?

AI chatbot compliance is the work of making a chatbot meet the laws that apply to it. Those laws cover four things: what the chatbot must disclose, what data it may process, what it may say, and what the business must be able to prove.
No single chatbot law exists. A customer service chatbot sits under several laws at once, and each one has its own scope.
Layer
Main laws
What it governs
AI transparency
EU AI Act Article 50, California AB 1609, Utah and Maine disclosure laws
Telling people they are talking to AI
Data protection
GDPR, HIPAA
Personal and health data in conversations
Consumer protection
FTC Act Section 5, state unfair trade practice laws
Deceptive claims and misleading answers
Sector and decision rules
Colorado SB 26-189, EU AI Act high-risk rules
Chatbots that help decide credit, jobs, housing, insurance, or care
Are AI chatbots illegal? No. No law covered in this guide bans a business from using an AI chatbot for customer service. The laws regulate how the chatbot is disclosed, what data it handles, and what it tells people.
For day-to-day operating rules beyond the legal minimum, see the chatbot best practices checklist.

What does the EU AI Act require from a customer service chatbot?

The EU AI Act requires a customer service chatbot to tell people they are interacting with an AI system. That duty comes from Article 50, and it has applied since 2 August 2026.

Article 50: the disclosure duty

Article 50(1) says providers must design AI systems that interact directly with people so that those people "are informed that they are interacting with an AI system". Article 50(5) says the information must come "in a clear and distinguishable manner at the latest at the time of the first interaction".
The European Commission's guidance on Article 50 adds two points:
  • Timing. People must be told from the start of the first interaction, and the notice must meet accessibility requirements.
  • The one exception. No notice is needed when it is obvious that the person is dealing with an AI system. The test is an average person who is reasonably well-informed, circumspect, and observant.
Relying on the exception is risky for a website chatbot. A named assistant with a human-sounding greeting is not obviously a machine to every visitor. A one-line disclosure removes the doubt.

Is a customer service chatbot high-risk under the EU AI Act?

A customer service chatbot is not high-risk under the EU AI Act in most cases. The European Commission places chatbots in the transparency risk category, where the duty is to make people aware they are interacting with a machine.
The classification changes with the job. A chatbot that helps decide access to credit, employment, education, or essential services can fall under the high-risk rules. The Commission lists education, employment, and credit scoring among the high-risk uses. Its AI Act overview says strict obligations for high-risk systems start on 2 December 2027.

Who must comply: the provider or the business using the chatbot?

The Article 50(1) duty sits with the provider, the company that builds the AI system. A business that runs a vendor's chatbot on its own website is a deployer.
In practice both sides have work to do. The vendor must make disclosure possible. The business controls the welcome message, so the business must check that the disclosure is switched on and worded clearly.
Under Article 2, the Act applies to providers that place AI systems on the EU market wherever they are established. It also applies to providers and deployers outside the EU when the system's output is used in the EU. A US company with EU visitors is in scope.
One more duty already applies. Article 4 requires providers and deployers to support the AI literacy of their staff, and it has applied since 2 February 2025.

EU AI Act fines for chatbot transparency

The maximum fine for breaking the Article 50 transparency duties is €15 million or 3% of worldwide annual turnover, whichever is higher. Article 99(4) sets that ceiling.
The higher tier of €35 million or 7% applies to the prohibited AI practices in Article 5. It does not apply to a missing chatbot disclosure.
Article 99(6) flips the rule for small and medium-sized companies. Their ceiling is the lower of the two figures.
Company
Worldwide annual turnover
3% of turnover
Article 50 fine ceiling
Large company
€1 billion
€30 million
€30 million (the higher figure)
Large company
€200 million
€6 million
€15 million (the higher figure)
SME
€10 million
€300,000
€300,000 (the lower figure)
These are ceilings. National authorities set the real amount case by case.

What do GDPR and HIPAA require from a chatbot?

GDPR and HIPAA govern the data in a chatbot conversation. GDPR covers personal data of people in the EU. HIPAA covers patient health information handled for US healthcare organizations.

GDPR: personal data in chat conversations

GDPR treats the business as the controller and the chatbot vendor as the processor. Article 28 says processing by a processor "shall be governed by a contract". That contract is the DPA.
A chatbot deployment needs four things under GDPR:
  1. A signed DPA with the vendor.
  1. A transfer mechanism, such as Standard Contractual Clauses, when the vendor processes data outside the EU.
  1. A privacy notice that visitors can reach from the chat.
  1. A way to answer access and erasure requests.
Article 83 sets fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher. The full list of duties is in GDPR chatbot requirements.
Vendors differ on where data is processed and on which plan includes a signed DPA. The comparison of GDPR-compliant chat platforms covers nine of them.

HIPAA: patient data in chat conversations

HIPAA applies when a chatbot handles protected health information (PHI) for a covered entity, such as a clinic, a hospital, or a health plan. The chatbot vendor then becomes a business associate.
The US Department of Health and Human Services says a covered entity may disclose PHI to a business associate if it obtains satisfactory assurances in a contract or other written arrangement. That contract is the BAA. No signed BAA means no PHI in the chat.
Vendors differ on which plan includes a BAA. Healthcare teams that need to know which plan each vendor's BAA requires can compare them in HIPAA compliant chatbots. The clauses to check are in what a chatbot BAA should cover.

Which US laws apply to AI chatbots?

The US has no single federal chatbot law. A customer service chatbot answers to the FTC Act nationwide and to a growing set of state laws, led by California.

FTC Act Section 5

Section 5 of the FTC Act bans unfair or deceptive acts or practices. It does not mention chatbots. It applies to them the same way it applies to any other sales or service channel.
In September 2024 the FTC announced Operation AI Comply, five enforcement actions against companies over deceptive AI claims. The FTC chair at the time said "there is no AI exemption from the laws on the books".
The FTC's maximum civil penalty is $53,088 per violation. It applies to knowing violations of FTC rules and to violations of FTC orders. The FTC set the figure in January 2025 and confirmed in September 2026 that it stays in place for 2026.

California: three laws, three scopes

California has three laws that touch chatbots. Only one targets customer service chatbots by name.
Law
In force
Who it covers
What it requires
Penalty
BOT Act (Business and Professions Code 17940 to 17943)
Since 1 July 2019
Anyone using a bot to talk to people in California online
Do not mislead a person about the bot's artificial identity to drive a sale or influence a vote. Disclosing the bot is a defense
None stated in the chapter itself
SB 243, companion chatbots
Since 1 January 2026
Operators of companion chatbots. Bots used only for customer service are excluded
AI disclosure and self-harm protocols
The greater of actual damages or $1,000 per violation
AB 1609, customer service chatbots
From 1 January 2027
Businesses with more than $500 million in gross annual revenue nationally
AI disclosure and a route to a human agent
Up to $5,000 for a first violation and $10,000 for each later one
AB 1609 was signed on 28 September 2026 as Chapter 733. It takes effect on 1 January 2027, the default date for a California statute signed in 2026. It sets four rules for a large private business:
  1. Do not represent that a customer service chatbot is a human.
  1. Give a clear and conspicuous disclosure when a reasonable person is likely to believe the chatbot is human.
  1. During regular business hours, give customers a simple way to ask for a customer service agent.
  1. Make a good faith effort to connect the customer to an agent within 15 minutes, or offer an appointment within one business day.
Public prosecutors enforce AB 1609. The law creates no private right of action. It exempts hospitals for healthcare communications, consumer reporting agencies, and some regulated utility services.
SB 243 defines a companion chatbot and then excludes "a bot that is used only for customer service". A support chatbot that answers product questions is outside it.
The BOT Act has no revenue threshold. A sales chatbot on a small company's website is covered, and a clear disclosure that it is a bot is the defense the statute provides.

Utah and Maine: disclosure laws that cover service chatbots

Utah and Maine both have disclosure laws that reach ordinary business chatbots.
  • Utah. A business must disclose that a person is interacting with generative AI when the person makes a clear and unambiguous request to know. Regulated occupations must disclose at the start of a high-risk interaction, such as one that collects health or financial data and gives personalized advice. The Division of Consumer Protection can fine $2,500 per violation. The 2025 amendments took effect on 7 May 2025, and the law is set to repeal in July 2027, according to Davis Polk's summary.
  • Maine. Title 10, section 1500-DD covers AI chatbots used in trade. A business may not use one in a way that may mislead a reasonable consumer into believing they are engaging with a human. A clear and conspicuous notice removes the problem. A violation is a violation of the Maine Unfair Trade Practices Act. The governor signed the law on 12 June 2025.

Washington HB 2225: companion chatbots only

Washington HB 2225 regulates AI companion chatbots and takes effect on 1 January 2027. The governor signed it on 24 March 2026.
The law excludes a bot used only for customer service, as long as the bot does not sustain a relationship across multiple interactions and generate outputs likely to elicit emotional responses. Companion chatbot operators must disclose that the chatbot is not human at the start of the interaction and at least every three hours. Violations fall under Washington's Consumer Protection Act.

Colorado SB 26-189: automated decisions, from 2027

Colorado replaced its 2024 AI Act before the law took effect. SB 26-189, signed on 14 May 2026, repeals and reenacts the earlier SB 24-205 with narrower rules.
The new law covers automated decision-making technology used in consequential decisions. Those are decisions about education, employment, housing, financial or lending services, insurance, healthcare services, and essential government services.
A chatbot that only answers questions is outside that definition. A chatbot that helps approve a loan or screen a job applicant is inside it. Deployers of covered systems must give clear and conspicuous notice at the point of interaction. Developer duties start on 1 January 2027.
The Colorado attorney general enforces the law under the Colorado Consumer Protection Act. Before 1 January 2030, the attorney general must give 60 days' notice and a chance to cure before bringing an action.

US chatbot laws at a glance

Jurisdiction
Law
Covers customer service chatbots?
Status
Federal
FTC Act Section 5
Yes, for deceptive practices
In force
California
BOT Act
Yes, for sales and election bots
In force since 1 July 2019
California
AB 1609
Yes, for businesses above $500 million in revenue
Takes effect 1 January 2027
California
SB 243
No, companion chatbots only
In force since 1 January 2026
Utah
Generative AI disclosure law
Yes, on request
In force, repeals July 2027
Maine
Title 10, section 1500-DD
Yes, in trade and commerce
Signed 12 June 2025
Washington
HB 2225
No, companion chatbots only
Takes effect 1 January 2027
Colorado
SB 26-189
Only when the chatbot influences a consequential decision
Duties start 1 January 2027

What are the penalties for a non-compliant chatbot?

The penalties for a non-compliant chatbot range from $1,000 per violation under California SB 243 to €20 million or 4% of worldwide turnover under GDPR. Each law has its own ceiling and its own enforcer.
Stat grid of maximum chatbot compliance penalties: EU AI Act Article 50, GDPR, FTC civil penalty, California AB 1609, Utah, and California SB 243
Stat grid of maximum chatbot compliance penalties: EU AI Act Article 50, GDPR, FTC civil penalty, California AB 1609, Utah, and California SB 243
Law
Maximum penalty
Who enforces
EU AI Act, Article 50
€15 million or 3% of worldwide annual turnover, whichever is higher
National authorities in each EU member state
GDPR
€20 million or 4% of worldwide annual turnover, whichever is higher
Data protection authorities
FTC Act
$53,088 per violation, for knowing rule violations and order violations
Federal Trade Commission
California AB 1609
$5,000 for a first violation, $10,000 for each later one
Public prosecutors
California SB 243
The greater of actual damages or $1,000 per violation
Private lawsuits by injured users
Utah
$2,500 per violation
Division of Consumer Protection
Per-violation penalties add up. Under AB 1609, 100 violations could reach $995,000. That is $5,000 for the first and $10,000 for each of the other 99.

Is a company liable for what its chatbot says?

A company can be liable for what its chatbot says. In February 2024, a British Columbia tribunal held Air Canada liable for negligent misrepresentation after its website chatbot gave a customer wrong information about bereavement fares.
The tribunal rejected the argument that the chatbot was responsible for its own words. It wrote that the chatbot "is still just a part of Air Canada's website", according to McCarthy Tetrault's summary of Moffatt v. Air Canada.
A disclosure does not fix a wrong answer. Grounding the chatbot in your own content and having it decline when the content has no answer lowers the risk. The guide to stopping chatbot hallucinations covers the controls.

Which chatbot laws apply to your business?

The chatbot laws that apply to your business depend on five facts: where users are, what data enters the chat, how large the business is, what the chatbot is for, and what it helps decide.
If your chatbot...
Then this applies
What to do
Can be used by people in the EU
EU AI Act Article 50 and GDPR
Disclose AI in the first message and sign a DPA with the vendor
Will receive patient health information
HIPAA
Sign a BAA before the first patient conversation
Serves California customers and the business has more than $500 million in gross annual revenue
California AB 1609, from 1 January 2027
Disclose AI and add a route to a human agent within 15 minutes
Sells to people in California
California BOT Act
Disclose that it is a bot
Serves consumers in Utah or Maine
State disclosure laws
Disclose AI clearly, and always answer truthfully when asked
Is built for companionship or emotional support
California SB 243, Washington HB 2225
Follow the companion chatbot rules, which go beyond this guide
Helps decide credit, jobs, housing, insurance, or care
Colorado SB 26-189, EU AI Act high-risk rules
Get legal advice before launch
Does none of the above
FTC Act Section 5
Do not let the chatbot pass as human or make false claims
Decision tree for which chatbot laws apply, based on EU users, patient data, business size, companion use, and consequential decisions
Decision tree for which chatbot laws apply, based on EU users, patient data, business size, companion use, and consequential decisions
A clear AI disclosure in the first message is what every disclosure law on this list asks for. Applying it to all visitors is simpler than per-state logic.

How do you make a chatbot compliant?

To make a chatbot compliant, work through five steps: disclosure, human handoff, data contracts, answer accuracy, and records. Each step below has one check.

Step 1: Disclose AI in the first message

Put the disclosure in the welcome message, where every visitor sees it before typing. Use plain words.
  • Clear: "Hi, I'm an AI assistant for Acme. I can answer questions about orders and returns. Ask for a person at any time."
  • Unclear: "Hi, I'm Sam from the Acme team. How can I help?"
Check: open the chat in a private browser window. The first message says the assistant is AI.

Step 2: Give visitors a route to a person

Show a way to reach a person in every conversation, and pass the transcript to the agent. AB 1609 turns this into law for large businesses in California from 1 January 2027.
Check: ask the chatbot for a human. Count the steps and the minutes until a person replies. Platforms differ on how much context reaches the agent, and the comparison of AI chatbots with human handoff covers that.

Step 3: Sign the data contracts

Sign a DPA with the vendor before personal data of EU residents enters the chat. Sign a BAA before any patient data does. Link the privacy policy inside the chat widget.
Check: the signed documents are on file, and the vendor's subprocessor list is saved with them. The clauses to read first are in what to look for in a chatbot DPA.

Step 4: Keep answers accurate

Limit the chatbot to content the business controls. Instruct it to say it does not know when the content has no answer. Route refunds, eligibility, and other commitments to a person or a fixed flow.
Check: ask ten questions the content cannot answer. The chatbot declines all ten.

Step 5: Keep records

Save the disclosure text and the date it went live. File the DPA and BAA. Log each handoff test. Name one person who owns the chatbot's compliance.
Check: a new team member can find all four records in under five minutes.

Worked example: a US software company with EU customers

This example uses a hypothetical company to show how the rules stack. The company sells software from Texas, has $40 million in annual revenue, and runs a support chatbot used by customers in the US and the EU.
Law
Applies?
Why
EU AI Act Article 50
Yes
The chatbot's output is used in the EU
GDPR
Yes
EU customers type personal data into the chat
California AB 1609
No
Revenue is below $500 million
California BOT Act
Yes, when the chatbot sells
It talks to people in California online
California SB 243, Washington HB 2225
No
The chatbot is used only for customer service
Colorado SB 26-189
No
The chatbot makes no consequential decisions
HIPAA
No
No patient data enters the chat
FTC Act Section 5
Yes
It covers deceptive practices in US commerce
The company's to-do list is short. It adds an AI disclosure to the welcome message, signs a DPA with its chatbot vendor, turns on human handoff, and files the records.

What must a chatbot vendor give you?

A chatbot vendor must give you three things for compliance: the contracts the law requires, the controls to disclose AI and hand off to a person, and clear answers on where data is processed.
What to ask for
Why it matters
Question to put to the vendor
Signed DPA
GDPR Article 28 requires a contract with every processor
Which plan includes a signed DPA, and can the text be read before purchase?
Signed BAA
HIPAA requires one before PHI is disclosed
Which plan includes a BAA, and will the vendor amend it?
Disclosure controls
EU AI Act Article 50 and US state laws
Can the welcome message be edited, and is there a permanent AI notice in the widget?
Human handoff
California AB 1609 and good practice
Does the agent receive the full transcript?
Subprocessor list and data location
GDPR transfer rules
Where is chat data processed, and under which transfer mechanism?

SiteGPT as one example

SiteGPT is an AI chatbot trained on a business's own content. This is how it answers the five questions above.
  • Disclosure. The welcome message is editable, and a disclaimer line can sit under the message box on any plan. HIPAA workspaces always show a fixed "Responses are AI-generated" line.
  • Human handoff. Human support is available on every plan. When a conversation escalates, the AI stops answering and the team replies.
  • DPA. A signed DPA comes with the Enterprise plan only. Baseline data processing terms for the other plans sit in the terms and conditions.
  • BAA. A HIPAA BAA is available on the Enterprise plan only. SiteGPT publishes its standard BAA and agrees reasonable changes during onboarding, such as retention windows and breach notice timelines.
  • Data location. SiteGPT has no EU data residency. Its service providers are mainly in the United States. Transfers rely on Standard Contractual Clauses, and SiteGPT names Article 27 representatives in the EU and the UK.
Three limits are worth knowing before you buy. The consent checkbox keeps no record of who accepted it, so proof of consent has to be collected another way. In a HIPAA workspace, cloud file connectors and chat integrations are not available. Content is added with website links, file uploads, and text snippets, and conversations stay in the chat on the website. SiteGPT describes its own security status as "SOC 2 Type II examined, GDPR certified, and HIPAA assessed".
Starter costs $59 per month billed monthly, or $39 per month billed yearly. Every self-serve plan has a 7-day free trial that requires a credit card.

Frequently asked questions

Basics

Are AI chatbots illegal?

AI chatbots are not illegal. No law in this guide bans a business from using one for customer service. The laws regulate disclosure, data handling, and deceptive answers.

What is chatbot compliance?

Chatbot compliance is meeting the laws that apply to a chatbot. For a customer service chatbot these are AI transparency rules, data protection law, and consumer protection law.

Do you have to tell users they are talking to an AI chatbot?

In the EU, yes. Article 50 of the EU AI Act has applied since 2 August 2026. In the US the answer depends on the state and the business. Utah, Maine, and California each have a disclosure rule, and deceiving customers about a bot can breach the FTC Act anywhere.

EU AI Act

Does the EU AI Act apply to customer service chatbots?

Yes. Article 50 covers AI systems intended to interact directly with people, and a customer service chatbot is one. The duty is to inform people that they are interacting with an AI system.

How is a customer service chatbot classified under the EU AI Act?

A customer service chatbot usually falls in the transparency risk category. It moves toward the high-risk category only when it helps make decisions in areas such as credit, employment, or access to essential services.

Does the EU AI Act apply to US companies?

Yes, when the chatbot's output is used in the EU. Article 2 covers providers and deployers established outside the EU in that case.

What is the fine for not disclosing an AI chatbot in the EU?

The ceiling is €15 million or 3% of worldwide annual turnover, whichever is higher. For small and medium-sized companies the ceiling is the lower of the two.

US laws

Which US states have chatbot disclosure laws?

California, Utah, and Maine have disclosure laws that reach business chatbots. California and Washington also have companion chatbot laws that exclude bots used only for customer service.

Does California SB 243 apply to customer service chatbots?

No. SB 243 covers companion chatbots and excludes a bot used only for customer service. California AB 1609 is the law for customer service chatbots, and it applies to businesses with more than $500 million in gross annual revenue from 1 January 2027.

Does the FTC regulate AI chatbots?

The FTC has no chatbot-specific rule. It uses Section 5 of the FTC Act, which bans deceptive practices, and it has brought AI cases under that law.

Data and contracts

Does a chatbot need a DPA?

Yes, when it processes personal data of people in the EU. GDPR Article 28 requires a contract between the business and the chatbot vendor.

Does a chatbot need a BAA?

Yes, when a healthcare organization lets patient health information into the chat. The BAA must be signed before the first patient conversation.

Is a disclaimer enough to make a chatbot compliant?

No. A disclaimer covers the disclosure duty only. Data contracts, human handoff, and accurate answers are separate duties.

Sources

All sources were opened and checked on 5 October 2026.

Give Your Customers The Experience That They Deserve

Create A Chatbot In Minutes, Today

Create Your Chatbot Now

Written by

Bhanu Teja P
Bhanu Teja P

Founder @ SiteGPT.ai & SourceSync.ai