Skip to content

Have an AI Chatbot on Your Website? From August 2026, You Need to Know Who Provides It

author: Jacek Sultan Automation and AI 7 minute read

Run a chatbot or custom AI assistant on your website? Who built it and whose brand it carries could determine your company's legal obligations. See what Article 50 of the AI Act changes and what you should check on your website starting 2 August 2026.

You add an AI chatbot to your site. It handles customer inquiries, draws on your company knowledge, and operates under your brand. You might assume you're simply using another business tool. The AI Act doesn't always see it that way.

Starting 2 August 2026, transparency rules for AI systems come into effect. In practice, this means you must inform users whenever they are speaking with artificial intelligence.

Before doing anything else, you need to answer a more fundamental question: in this specific implementation, who is legally the provider of the AI system?

An Off-the-Shelf Chatbot and a Custom AI Assistant Are Not the Same Thing

The AI Act distinguishes between the provider of an AI system and the entity that deploys it.

If your company uses a ready-made system from a third-party vendor—without substantial modifications and under their branding—the situation is fairly straightforward. The vendor remains the provider, and your company is the deployer.

Things change, however, if the system was built specifically for your company and runs under your name.

The legal definition of a provider also covers any entity that commissions the development of an AI system and then places it on the market or puts it into service under its own name or trademark.

That is why a custom customer service chatbot, an internal AI agent for staff, or a bespoke company assistant can entail very different legal obligations than simply paying for a standard SaaS subscription.

Using OpenAI, Anthropic, or Any Other Model Doesn't Settle the Matter

This distinction is crucial in modern AI projects.

A company might rely on an external language model under the hood, but build a bespoke system around it. That assistant can feature a custom user interface, tap into internal documents, connect to a CRM, draft quotes, carry out actions, and operate entirely under your brand.

In that scenario, simply pointing to the company behind the foundation model doesn't settle your own company's legal role.

You have to evaluate the entire system: how it was built, the brand it carries, and who actually makes it available to end users.

What Changes When You Become a Provider?

One of the most visible obligations relates to how you interact with end users.

If an AI system interacts directly with humans, it must be designed and developed so that users are informed they are interacting with AI, unless this is obvious from the circumstances.

For a standard chatbot on a corporate website, never assume the user will simply figure it out on their own.

This disclosure should be directly tied to the interaction and clearly visible to the person using the system. Tucking it away in your terms of service or privacy policy does not give users that information when they are actually interacting with the bot.

Is It Enough to Call It an "Assistant"?

Don't assume a clever label solves the problem.

Labels like "assistant," "advisor," "concierge," or a first name do not make it clear whether a customer is talking to a human or an AI system.

This becomes an issue especially when a chatbot is given a human name, a profile photo or avatar that looks like an employee, and writes in the tone of a real support agent.

The safer approach is a clear, upfront message displayed right when the chat opens—stating simply that the user is talking to an AI assistant.

You don't need to turn the chat box into a legal agreement. The note can be brief, natural, and built cleanly into the UI.

The Chatbot Should Also Know It Is an AI

Try a very simple test.

Ask your chatbot: "Are you human?"

If it dodges the question, introduces itself as a team member, or hints that it's a real person, your system prompt needs work.

This is critical for systems powered by large language models. A static label in the UI shouldn't be your only safeguard. The assistant's actual behaviour must match its true identity.

What About AI Used Only by Employees?

Context matters.

A public chatbot open to any website visitor is not treated the same way as an internal assistant used by staff who already know what tool they are working with.

That is why any implementation plan should define not just the features of the system, but also who will be using it.

A customer-facing store agent, an internal sales copilot, and a developer tool for reviewing code may all share similar foundations, but they come with different requirements.

The AI Act Also Applies to AI-Generated Content

Chatbots aren't the only area worth auditing.

Companies routinely use AI to draft product descriptions, blog posts, visuals, photos, marketing assets, and other content published across their websites.

This does not mean every single piece of copy generated with AI needs an explicit disclaimer.

Article 50 sets out specific rules for cases like deepfakes and text published to inform the public on matters of public interest.

Human oversight also counts. For certain types of content, editorial review and human responsibility can remove the disclosure requirement.

A brand publishing hundreds of product descriptions shouldn't rush to label every item "generated by AI" come August. Review the types of content you create and how they are handled before publishing.

Watch Out for Post-Approval Automations

An interesting edge case occurs when a human reviews and approves copy, but an automated AI pipeline alters it afterward.

This might include automatic copy optimization, section rewrites, automated summaries, or other processing triggered after editorial sign-off.

When auditing your AI footprint, asking your team if they use ChatGPT is not enough.

Audit your CMS, plugins, background integrations, and automated workflows. In larger companies, the list of touchpoints where AI touches or alters content is often much longer than anticipated.

What to Check on Your Website

Start by cataloguing every AI system that visitors interact with, directly or indirectly.

If you run a chatbot, clarify who built it, whose brand it displays, and who deployed it. Make sure users clearly understand they are interacting with AI before a conversation begins.

Next, audit what content is produced with AI and where it appears. Review copy, images, video assets, and other synthetic media separately.

Review your editorial workflow. When humans review AI output, make sure it's clear who reviews it and who carries editorial responsibility.

Finally, check your background automations. A pipeline that generates product specs, an agent drafting articles, and a customer-facing bot might serve distinct workflows, even if they share the same underlying models.

It's Not Just About Adding an "AI" Label

The simplest mistake is treating these regulations as nothing more than an extra banner to add to the page.

In practice, the priority is understanding what AI systems operate within your business and your company's legal role for each of them.

Only then can you identify where notices are required, which content needs human sign-off, and which responsibilities belong to the third-party tool vendor versus your own business.

This is especially critical for custom-built solutions. The more tailored an assistant, agent, or bot is to your operations, the more important it is to define these legal and technical roles during the design phase.

Deploying a Chatbot or AI Agent?

At DOCK, we design and build AI assistants, agents, and automations for businesses. They can tap into company knowledge, draft documents, support internal teams, and interact directly with your software stack.

For every project, we look beyond raw model capabilities to account for user communication, human oversight, data access, and transparency requirements from day one.

That way, AI Act compliance isn't a hasty patch slapped on an existing tool—it's part of the architecture from the start.

Any questions?

Do I have to label every piece of AI-written text on my website?

No. Article 50(4), second subparagraph applies to text published to inform the public on matters of public interest, such as public health, consumer rights, environmental protection, or public administration. European Commission guidelines identify product descriptions and advertising copy as examples outside the scope of this rule, provided they do not make claims regarding health, consumer safety, or sustainability.

Does embedding an off-the-shelf SaaS chatbot widget make me a provider?

No, provided you use it without modifications or custom components; the software vendor remains the provider. You become a provider if the system was custom-built for you or developed in-house and operates under your name, or if you modify someone else's generative system and place it into service under your brand.

Do contents published before 2 August 2026 need to be labelled retroactively?

No. European Commission guidelines state that content generated before 2 August 2026 does not require retroactive labelling, though the Commission encourages it. There is one caveat: text generated earlier but published on or after 2 August does require disclosure, as the publication date is what counts.

Does sentiment analysis on customer reviews qualify as an emotion recognition system?

No, not if it processes text only. The definition under Article 3(39) of the AI Act requires the system to identify or infer emotions or intentions based on biometric data. A camera assessing a person's mood or age falls under Article 50(3), meaning the deployer must inform individuals exposed to it.

Does a rules-based chatbot fall under Article 50(1)?

No, as long as it does not meet the definition of an AI system. The guidelines explicitly exclude simple, non-AI automated answering tools, such as out-of-office autorepliers or predefined, rules-based FAQ responders. What matters is the definition of an AI system under Article 3(1), not the visual chat widget on the page.

Are businesses required to sign the Code of Practice on AI content transparency?

No, signing is voluntary and opting out is not a breach of the AI Act. The Code was published on 10 June 2026; signatories—both providers under Article 50(2) and deployers under Article 50(4)—benefit from a simplified path to prove compliance. Non-signatories simply need to demonstrate compliance through other appropriate means.

What are the penalties for failing to label AI content or display an AI disclosure?

Violations of obligations under Article 50 carry administrative fines of up to EUR 15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For small and medium-sized enterprises, the lower of these amounts applies. In Poland, supervision is set to be carried out by the Commission for AI Development and Safety, which, according to the Ministry of Digital Affairs, will launch in November 2026.

Jacek Sultan

Technical Solutions Architect

CTO and co-founder of Dock. Focused on web application development, system architecture, and infrastructure. He combines a technical approach with a business perspective, focusing on solutions that are simple, reliable, and make business sense. He values practicality in technology. A good solution should not only work well, but also deliver clear value.

Chat with us