You add an AI chatbot to your site. It handles customer inquiries, draws on your company knowledge, and operates under your brand. You might assume you're simply using another business tool. The AI Act doesn't always see it that way.
Starting 2 August 2026, transparency rules for AI systems come into effect. In practice, this means you must inform users whenever they are speaking with artificial intelligence.
Before doing anything else, you need to answer a more fundamental question: in this specific implementation, who is legally the provider of the AI system?
An Off-the-Shelf Chatbot and a Custom AI Assistant Are Not the Same Thing
The AI Act distinguishes between the provider of an AI system and the entity that deploys it.
If your company uses a ready-made system from a third-party vendor—without substantial modifications and under their branding—the situation is fairly straightforward. The vendor remains the provider, and your company is the deployer.
Things change, however, if the system was built specifically for your company and runs under your name.
The legal definition of a provider also covers any entity that commissions the development of an AI system and then places it on the market or puts it into service under its own name or trademark.
That is why a custom customer service chatbot, an internal AI agent for staff, or a bespoke company assistant can entail very different legal obligations than simply paying for a standard SaaS subscription.
Using OpenAI, Anthropic, or Any Other Model Doesn't Settle the Matter
This distinction is crucial in modern AI projects.
A company might rely on an external language model under the hood, but build a bespoke system around it. That assistant can feature a custom user interface, tap into internal documents, connect to a CRM, draft quotes, carry out actions, and operate entirely under your brand.
In that scenario, simply pointing to the company behind the foundation model doesn't settle your own company's legal role.
You have to evaluate the entire system: how it was built, the brand it carries, and who actually makes it available to end users.
What Changes When You Become a Provider?
One of the most visible obligations relates to how you interact with end users.
If an AI system interacts directly with humans, it must be designed and developed so that users are informed they are interacting with AI, unless this is obvious from the circumstances.
For a standard chatbot on a corporate website, never assume the user will simply figure it out on their own.
This disclosure should be directly tied to the interaction and clearly visible to the person using the system. Tucking it away in your terms of service or privacy policy does not give users that information when they are actually interacting with the bot.
Is It Enough to Call It an "Assistant"?
Don't assume a clever label solves the problem.
Labels like "assistant," "advisor," "concierge," or a first name do not make it clear whether a customer is talking to a human or an AI system.
This becomes an issue especially when a chatbot is given a human name, a profile photo or avatar that looks like an employee, and writes in the tone of a real support agent.
The safer approach is a clear, upfront message displayed right when the chat opens—stating simply that the user is talking to an AI assistant.
You don't need to turn the chat box into a legal agreement. The note can be brief, natural, and built cleanly into the UI.
The Chatbot Should Also Know It Is an AI
Try a very simple test.
Ask your chatbot: "Are you human?"
If it dodges the question, introduces itself as a team member, or hints that it's a real person, your system prompt needs work.
This is critical for systems powered by large language models. A static label in the UI shouldn't be your only safeguard. The assistant's actual behaviour must match its true identity.
What About AI Used Only by Employees?
Context matters.
A public chatbot open to any website visitor is not treated the same way as an internal assistant used by staff who already know what tool they are working with.
That is why any implementation plan should define not just the features of the system, but also who will be using it.
A customer-facing store agent, an internal sales copilot, and a developer tool for reviewing code may all share similar foundations, but they come with different requirements.
The AI Act Also Applies to AI-Generated Content
Chatbots aren't the only area worth auditing.
Companies routinely use AI to draft product descriptions, blog posts, visuals, photos, marketing assets, and other content published across their websites.
This does not mean every single piece of copy generated with AI needs an explicit disclaimer.
Article 50 sets out specific rules for cases like deepfakes and text published to inform the public on matters of public interest.
Human oversight also counts. For certain types of content, editorial review and human responsibility can remove the disclosure requirement.
A brand publishing hundreds of product descriptions shouldn't rush to label every item "generated by AI" come August. Review the types of content you create and how they are handled before publishing.
Watch Out for Post-Approval Automations
An interesting edge case occurs when a human reviews and approves copy, but an automated AI pipeline alters it afterward.
This might include automatic copy optimization, section rewrites, automated summaries, or other processing triggered after editorial sign-off.
When auditing your AI footprint, asking your team if they use ChatGPT is not enough.
Audit your CMS, plugins, background integrations, and automated workflows. In larger companies, the list of touchpoints where AI touches or alters content is often much longer than anticipated.
What to Check on Your Website
Start by cataloguing every AI system that visitors interact with, directly or indirectly.
If you run a chatbot, clarify who built it, whose brand it displays, and who deployed it. Make sure users clearly understand they are interacting with AI before a conversation begins.
Next, audit what content is produced with AI and where it appears. Review copy, images, video assets, and other synthetic media separately.
Review your editorial workflow. When humans review AI output, make sure it's clear who reviews it and who carries editorial responsibility.
Finally, check your background automations. A pipeline that generates product specs, an agent drafting articles, and a customer-facing bot might serve distinct workflows, even if they share the same underlying models.
It's Not Just About Adding an "AI" Label
The simplest mistake is treating these regulations as nothing more than an extra banner to add to the page.
In practice, the priority is understanding what AI systems operate within your business and your company's legal role for each of them.
Only then can you identify where notices are required, which content needs human sign-off, and which responsibilities belong to the third-party tool vendor versus your own business.
This is especially critical for custom-built solutions. The more tailored an assistant, agent, or bot is to your operations, the more important it is to define these legal and technical roles during the design phase.
Deploying a Chatbot or AI Agent?
At DOCK, we design and build AI assistants, agents, and automations for businesses. They can tap into company knowledge, draft documents, support internal teams, and interact directly with your software stack.
For every project, we look beyond raw model capabilities to account for user communication, human oversight, data access, and transparency requirements from day one.
That way, AI Act compliance isn't a hasty patch slapped on an existing tool—it's part of the architecture from the start.