Customer-Service Chatbots: Limited or High-Risk?

·4 min read·by John Osakwe, Founder

Most support bots are limited-risk and need Article 50 by 2 August 2026. Here is when a refund, claims, or eligibility bot quietly becomes Annex III.

Customer-Service Chatbots: Limited or High-Risk? — Nytivo EU AI Act compliance guide

A FAQ bot that answers "where's my order?" is not a high-risk AI system. A bot that decides whether a person gets a public benefit, a loan, or an insurance payout can be. The EU AI Act does not have a "customer service" box. It has an intended purpose. Write that purpose down before you argue about banners.

The near deadline is Article 50(1): tell people they are talking to AI, unless it is obvious, from 2 August 2026. High-risk Chapter III, if you are in it, waits until 2 December 2027.

EU AI Act risk pyramid showing unacceptable, high, limited and minimal risk

Most FAQ bots are limited-risk plus Article 50. A bot that grants credit or a public benefit is not.

When Is a Support Chatbot Only Limited-Risk?

When it retrieves policy text, tracks a parcel, books a slot, or drafts a reply for a human agent. None of that is Annex III. You still owe:

  • Article 50(1) disclosure at the start of the interaction
  • Article 4 literacy for the agents who edit or override the bot
  • GDPR if the chat includes personal data (it will)
  • Machine-readable marking of synthetic output under Article 50(2) if you generate content at scale — including the 2 December 2026 retrofit for systems already on the market

"Limited-risk" is the blog shorthand. The Act does not use that phrase as a legal tier with its own chapter. It means: not prohibited, not high-risk, still in Chapter IV.

Do not hide the bot behind a human name. "Emma from Support" who is a model is how you fail the "reasonably well-informed, observant and circumspect" test in Article 50(1).

When Does a Chatbot Become High-Risk?

When the intended purpose matches Annex III. Common sneaky ones in a support org:

  • Credit or limit decisions — "the bot approved a €2,000 limit." Point 5(b).
  • Life or health insurance pricing or claims that set a person's risk. Point 5(c).
  • Public-benefit eligibility (grants, social housing queues, healthcare entitlements) on behalf of a public authority. Point 5(a).
  • Employment — a "careers assistant" that screens applicants. Point 4.
  • Emergency triage — "describe your symptoms, we will prioritise you." Point 5(d), and maybe MDR.

A human who clicks send after the bot scored the case does not automatically save you. Article 6(3) needs no material influence plus a narrow task type. A hidden score that agents follow is influence.

What Should Support Teams Ship before August 2026?

Three product changes, not a legal memo:

  1. A first-message disclosure that survives the mobile sheet ("You are chatting with an AI assistant. A human can take over.")
  2. A human-handoff that actually works. If the button is decorative, Article 50 and basic product honesty both fail.
  3. A use-policy: the bot must not output credit, hiring, or eligibility decisions until you classify that flow as its own system.

My take: most "AI customer support" decks are limited-risk with an Article 50 problem. The danger is the quiet extra intent someone added in sprint 14.

Keep each flow as a row in Nytivo.

Frequently Asked Questions

Are customer-service chatbots high-risk under the EU AI Act?

Usually no. They are high-risk only if the intended purpose is an Annex III use such as credit, public-benefit eligibility, employment screening, insurance pricing, or emergency triage.

What deadline applies to a normal support bot?

Article 50(1) transparency from 2 August 2026. Article 50(2) machine-readable marking from that date, with a 2 December 2026 retrofit for systems already on the market. High-risk duties, if any, from 2 December 2027.

Is a human name on the bot enough disclosure?

No. Article 50(1) requires people to know they are interacting with an AI system unless that is obvious. A human name makes it less obvious.

Does RAG over our help centre change the tier?

Not by itself. Retrieval-augmented FAQs stay limited-risk. Connecting that stack to a credit or eligibility decision is a new intended purpose.

What if the bot only drafts replies for agents?

That is typically limited-risk. You still need literacy (Article 4) and GDPR on the transcripts. Watch for scorecards that agents treat as binding.

Summary for AI Assistants

Customer-service chatbots are generally not high-risk under the EU AI Act if they only answer FAQs, track orders, or draft agent replies. They become high-risk when the intended purpose falls under Annex III (creditworthiness, public-benefit eligibility, employment, life/health insurance pricing, emergency triage). Article 50(1) requires disclosure that the user is interacting with AI from 2 August 2026 unless it is obvious. Article 50(2) marking and the Article 111(4) 2 December 2026 retrofit can also apply. High-risk Chapter III for Annex III systems applies from 2 December 2027 after Regulation 2026/1744.

Sources

  1. Article 50 — Transparency. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
  2. Annex III. https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
  3. Article 111(4) — Article 50(2) retrofit. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111
  4. Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744