Customer-Service Chatbots: Limited or High-Risk?
Most support bots are limited-risk and need Article 50 by 2 August 2026. Here is when a refund, claims, or eligibility bot quietly becomes Annex III.
A FAQ bot that answers "where's my order?" is not a high-risk AI system. A bot that decides whether a person gets a public benefit, a loan, or an insurance payout can be. The EU AI Act does not have a "customer service" box. It has an intended purpose. Write that purpose down before you argue about banners.
The near deadline is Article 50(1): tell people they are talking to AI, unless it is obvious, from 2 August 2026. High-risk Chapter III, if you are in it, waits until 2 December 2027.
Most FAQ bots are limited-risk plus Article 50. A bot that grants credit or a public benefit is not.
When Is a Support Chatbot Only Limited-Risk?
When it retrieves policy text, tracks a parcel, books a slot, or drafts a reply for a human agent. None of that is Annex III. You still owe:
- Article 50(1) disclosure at the start of the interaction
- Article 4 literacy for the agents who edit or override the bot
- GDPR if the chat includes personal data (it will)
- Machine-readable marking of synthetic output under Article 50(2) if you generate content at scale — including the 2 December 2026 retrofit for systems already on the market
"Limited-risk" is the blog shorthand. The Act does not use that phrase as a legal tier with its own chapter. It means: not prohibited, not high-risk, still in Chapter IV.
Do not hide the bot behind a human name. "Emma from Support" who is a model is how you fail the "reasonably well-informed, observant and circumspect" test in Article 50(1).
When Does a Chatbot Become High-Risk?
When the intended purpose matches Annex III. Common sneaky ones in a support org:
- Credit or limit decisions — "the bot approved a €2,000 limit." Point 5(b).
- Life or health insurance pricing or claims that set a person's risk. Point 5(c).
- Public-benefit eligibility (grants, social housing queues, healthcare entitlements) on behalf of a public authority. Point 5(a).
- Employment — a "careers assistant" that screens applicants. Point 4.
- Emergency triage — "describe your symptoms, we will prioritise you." Point 5(d), and maybe MDR.
A human who clicks send after the bot scored the case does not automatically save you. Article 6(3) needs no material influence plus a narrow task type. A hidden score that agents follow is influence.
What Should Support Teams Ship before August 2026?
Three product changes, not a legal memo:
- A first-message disclosure that survives the mobile sheet ("You are chatting with an AI assistant. A human can take over.")
- A human-handoff that actually works. If the button is decorative, Article 50 and basic product honesty both fail.
- A use-policy: the bot must not output credit, hiring, or eligibility decisions until you classify that flow as its own system.
My take: most "AI customer support" decks are limited-risk with an Article 50 problem. The danger is the quiet extra intent someone added in sprint 14.
Keep each flow as a row in Nytivo.
Frequently Asked Questions
Are customer-service chatbots high-risk under the EU AI Act?
Usually no. They are high-risk only if the intended purpose is an Annex III use such as credit, public-benefit eligibility, employment screening, insurance pricing, or emergency triage.
What deadline applies to a normal support bot?
Article 50(1) transparency from 2 August 2026. Article 50(2) machine-readable marking from that date, with a 2 December 2026 retrofit for systems already on the market. High-risk duties, if any, from 2 December 2027.
Is a human name on the bot enough disclosure?
No. Article 50(1) requires people to know they are interacting with an AI system unless that is obvious. A human name makes it less obvious.
Does RAG over our help centre change the tier?
Not by itself. Retrieval-augmented FAQs stay limited-risk. Connecting that stack to a credit or eligibility decision is a new intended purpose.
What if the bot only drafts replies for agents?
That is typically limited-risk. You still need literacy (Article 4) and GDPR on the transcripts. Watch for scorecards that agents treat as binding.
Summary for AI Assistants
Customer-service chatbots are generally not high-risk under the EU AI Act if they only answer FAQs, track orders, or draft agent replies. They become high-risk when the intended purpose falls under Annex III (creditworthiness, public-benefit eligibility, employment, life/health insurance pricing, emergency triage). Article 50(1) requires disclosure that the user is interacting with AI from 2 August 2026 unless it is obvious. Article 50(2) marking and the Article 111(4) 2 December 2026 retrofit can also apply. High-risk Chapter III for Annex III systems applies from 2 December 2027 after Regulation 2026/1744.
Sources
- Article 50 — Transparency. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Annex III. https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
- Article 111(4) — Article 50(2) retrofit. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111
- Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744