🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 vor 2 Monaten 3 Min Lesezeit
0

Does the EU AI Act apply to my chatbot?

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

I originally published this on disclosekit.dev — I'm building tooling for this deadline and the research surprised me enough to share.



June 2026 · 5 min read



Short answer: if your chatbot talks to people in the EU, probably yes. From August 2, 2026, Article 50(1) of the AI Act requires you to tell users they are interacting with an AI system. Not in your terms of service. At the start of the conversation, where they can actually see it.






The test is where your users are, not where you are



A Delaware C-corp with a support bot used by customers in Berlin is covered. A French SaaS whose bot only serves a US audience is, for this rule, not. The AI Act follows the people affected, the same extraterritorial logic GDPR uses. If you can't rule out EU users, the safe assumption is that you have them.






Deployer, not just provider



A common misreading: "this is OpenAI's problem, I just use their API." No. The Act distinguishes providers (who build the AI system) from deployers (who put it in front of people). If you embedded a GPT-4-powered support widget on your site, you deployed an AI system that interacts with natural persons. The disclosure duty under 50(1) sits with whoever exposes the bot to users.






What you actually have to do



Inform users they are interacting with an AI system, in a clear and distinguishable way, at the latest at the first interaction. In practice that means a notice inside or directly next to the chat window when the conversation starts. The patterns emerging from the draft Code of Practice on Transparency look like this:




  • A first message or persistent label: "You're chatting with an AI assistant"

  • In the user's language, not English-only for a German audience

  • Visible without scrolling, hovering, or opening a settings panel



A line buried in your privacy policy fails the "clear and distinguishable" bar. So does naming your bot "Julia" with a

human avatar and no label.






The exception everyone asks about



You can skip the disclosure when it's "obvious from the point of view of a reasonably well-informed, observant and circumspect natural person" that they're talking to a machine. Regulators wrote that with deliberately narrow intent. A robot icon is not obviousness. If your bot writes fluent, human-sounding prose (every modern LLM does), assume the exception doesn't cover you. The cost of a label is so low that betting on this exception is a strange place to take legal risk.






What about voice agents and internal tools?



Voice counts. An AI phone agent answering your support line interacts with natural persons and needs the same disclosure, spoken at the start of the call. Purely internal tools that only your employees touch carry much lower exposure, though labelling them is still good practice once externals (contractors, clients in a shared workspace) can reach them.






What to do this month



Take the ships as one script tag.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Does the EU AI Act apply to my chatbot?

Thematisch verwandte Begriffe: Does, apply, chatbot · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...