Neodigit

Pillar · Automation & AI

AI Chatbots, GDPR and the AI Act: What Changes on August 2, 2026

The essentials

A chatbot or AI agent that processes personal data remains fully subject to GDPR, regardless of the model used. The European AI Act adds stronger disclosure and transparency obligations starting August 2, 2026, with fines that can reach €15 to €20 million or 3 to 4% of global revenue depending on the severity of the breach.

Two regulations, two different angles

GDPR governs the processing of personal data: legal basis for collection, retention period, right of access and deletion, storage security. An AI agent that answers a customer based on their purchase history, or that processes a form containing personal data, falls under this framework exactly like any other IT processing.

The AI Act governs the use of the AI system itself: risk level, transparency toward the end user, technical documentation, human oversight. A chatbot interacting with individuals must, for example, clearly state that it’s an AI and not a human, unless that’s already obvious from context.

The two regulations stack: complying with one doesn’t exempt you from the other.

The August 2, 2026 deadline

The AI Act’s implementation timeline has been progressive since it came into force in 2024. August 2, 2026 marks an important milestone: strengthened transparency and disclosure obligations for many AI systems used in businesses, including chatbots and conversational agents aimed at the public.

Concretely, this means for most SMEs using a customer-facing AI agent:

  • Clearly informing the user they’re interacting with an AI
  • Documenting the system’s general operation (purpose, data used, known limitations)
  • Providing a recourse mechanism to a human contact for sensitive cases
  • Keeping a traceability record of automated decisions with a significant impact on a person

The penalties at stake

The AI Act’s penalty regime is tiered by severity, with amounts that can reach €15 to €20 million or 3 to 4% of a company’s annual global revenue for the most serious breaches. On top of that come classic GDPR penalties (up to 4% of global revenue or €20 million), which can stack depending on the nature of the breach found.

These amounts primarily target the most serious breaches; the vast majority of good-faith SMEs that properly document their system and follow transparency principles aren’t the target of these maximum penalties. But a complete absence of any compliance effort is a real risk, especially as enforcement strengthens along with the rules coming into force.

How we build compliance into our projects

Scoping the legal basis and purpose before any development: what data is processed, for what use, with what retention period.

Hosting adapted to the sensitivity level: data hosted in France or on-premise on your servers when the nature of the data requires it, rather than defaulting to generic cloud hosting.

Transparency built in from the design phase: a clear statement of the AI nature of the interaction, accessible and understandable documentation of how the system works, not just an unreadable legal notice at the bottom of the page.

Human oversight on high-impact decisions: an AI agent that influences a significant decision (order refusal, customer scoring, case prioritization) always includes a human checkpoint or recourse.

This approach ties into the security and compliance logic we apply more broadly across our projects, detailed on the technical governance page.

FAQ

Does an AI chatbot need to comply with GDPR and the European AI Act? Yes, both regulations apply and stack as soon as the chatbot processes personal data or interacts with individuals. GDPR governs the data processed, the AI Act governs the transparency and use of the AI system itself.

What concretely changes on August 2, 2026 for an SME? Stronger transparency and disclosure obligations for public-facing AI systems: clearly informing the user they’re talking to an AI, documenting how the system works, providing human recourse for sensitive cases.

What penalties apply for non-compliance? Up to €15 to €20 million or 3 to 4% of global revenue for the most serious AI Act breaches, on top of which classic GDPR penalties can apply. Good-faith SMEs that document their approach aren’t the primary target of these maximum amounts, but a total absence of compliance is a real and growing risk.

Let’s review your AI project’s compliance. A 30-minute audit identifies the adjustments needed before they become urgent.