At first glance, a chatbot appears to be a simple tool: a chat window, a few automated responses, a smooth user experience. This apparent simplicity is misleading. Behind the interface lies a stack of legal rules that all apply at the same time.
The Russian doll image sums up the situation well. A chatbot is not governed by a single law, but by several.
This article offers a simple reading of these layers, within the European context, and a method for approaching them in the correct order.
A chatbot does much more than answer questions. It processes personal data, interacts with customers, sometimes with minors, it can influence a decision, recommend a product, filter a request. Each of these dimensions activates a different set of rules.
In Europe, two major texts almost always overlap.
The European Union's Artificial Intelligence Act (AI Act) regulates AI systems according to their level of risk. A chatbot is subject to transparency obligations under this act, and even more so if it is used for sensitive decisions.
The GDPR applies whenever a chatbot processes personal data, which is almost always the case: there must be a legal basis, transparency, a controlled retention period, and respect for individuals’ rights.
To these two pillars are added, depending on the context, consumer law, rules for the protection of minors, cybersecurity, or rules on targeted advertising and cookies. The question is therefore never «which law applies?» but «how many layers apply, and which ones?».
If there is one requirement that runs through almost all regulations, in Europe and elsewhere, it is this: The user must be clearly informed that they are interacting with an artificial intelligence, not a human.
In Europe, this requirement is set out in the transparency obligations of the AI Act: to disclose the artificial nature of the interlocutor, to label AI-generated content, and to flag hyper-manipulations. This is the first layer – the most universal, and often the simplest to implement.
There is, however, one caveat: where the context makes it clear to any reasonable person that they are interacting with an AI, explicit information may not be required. But this exception must be assessed on a case-by-case basis, taking into account the overall user experience, and must not be assumed simply for the sake of convenience.
Not all layers are created equal. Some only activate in more sensitive cases, and these are the most demanding.
A chatbot that merely answers general questions does not have the same status as a chatbot capable of influencing a decision that affects an individual: access to credit, healthcare, training or employment. In the latter case, the system may fall within the ‘high-risk’ category under the AI Act, which triggers significant obligations: risk management, data governance, human oversight, technical documentation, compliance assessment and, in some cases, a fundamental rights impact assessment.
In
One point deserves particular vigilance: the protection of minors. The use of chatbots, particularly companion chatbots, by children and adolescents is attracting increasing regulatory attention, in response to recent incidents.
If your chatbot is likely to be used by minors, or if it does not clearly exclude them, this layer is added to others and imposes enhanced precautions: age verification, adaptation of interactions, restrictions on certain types of content, specific information obligations.
This is a point to examine beforehand, not once the chatbot has been deployed.
Faced with this backlog, the right strategy is not to tackle everything at once.
It involves working in layers, from the outermost to the deepest.
Step 1: Map out usage patterns. For each use of the chatbot, identify the data processed, the systems mobilised, the flows and the audiences concerned. One cannot govern what one has not mapped.
Step 2: Identify sensitive uses. Identify situations in which the chatbot makes, or helps to make, a decision that significantly affects a person. It is these uses that may trigger the most significant obligations.
Step 3: Define information modalities. To determine when and how users should be informed that they are interacting with an AI.
Step 4: Engage the right stakeholders. A chatbot’s compliance is not solely a legal matter. It requires collaboration between the product, technical, security and compliance teams in order to design an experience that is both compliant and feasible.
Step 5: Keep a close watch on developments. The regulatory landscape is changing rapidly. What is compliant today may no longer be so tomorrow. New requirements are emerging regularly, whilst regulators’ initial decisions are beginning to clarify how these are to be interpreted and applied.
A well-designed chatbot gives the user a sense of simplicity. But this apparent simplicity, when done properly, is underpinned by compliance work that has unravelled and correctly organised all the relevant layers.
Let’s return to the image of the Russian nesting doll: most organisations would be well advised to start with the outermost layer – transparency – and then tackle the inner layers one by one, depending on their practices, their audiences and their data. It is not the technical sophistication of the chatbot that protects the organisation; it is the rigour with which it has identified, prior to deployment, all the rules that apply to it.
Because a chatbot is never just a chatbot. It is a simple interface built on a stack of responsibilities. To see them all is to begin to master them.
Yes. Whenever a chatbot processes personal data, including that of employees or internal staff, the GDPR applies. The legal basis, retention period and the rights of data subjects must be taken into account, regardless of the system’s audience.
The distinction rests mainly on the impact of the decisions that the chatbot influences. A chatbot capable of affecting a person's access to credit, healthcare, employment, or training falls into the high-risk category. A general informational chatbot is subject to lighter obligations, particularly regarding transparency.
Not necessarily in every message, but the information must be clear and accessible before or at the start of the interaction. The exception – where the context makes the artificial nature of the interaction obvious – must be applied strictly and cannot be used as a default justification.
As early as possible — ideally before the design phase. Building compliance in at an early stage (the "privacy by design" and "compliance by design" approaches) is far less costly than rectifying shortcomings after deployment. This is particularly true for high-risk uses and contexts involving minors.
The compliance of an AI chatbot is multidisciplinary. It involves legal and compliance teams, but also product teams (for design choices), technical teams (for security measures), and IT security. A DPO (Data Protection Officer) must be consulted as soon as personal data is processed.
We use cookies to improve your experience. Some features may not work without them. Manage your preferences.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper functioning of the website.
You will find more information in our...Cookie Policy and Terms & Conditions of Sale.