← Back to blog
·8 min read

Two rules, both correct: what the EU AI Act actually asks of a business using an AI assistant

European law says a conversational system must tell people it isn't human. A client's brand guidelines said never sound technical with patients. Both rules were correct. Here's how we resolved it — and what the AI Act actually asks of an ordinary business.

Two open rulebooks side by side on a dark desk, one with an EU-style circle of stars, the other a brand style guide, with a phone showing a chat bubble between them.

Two rules landed on the same build, a week apart, and pointed in opposite directions.

The first came from European law: a system that holds a conversation with a person has to tell that person it isn't human. Plainly, not buried.

The second came from the client — a healthcare business running a medically supervised health programme. Their brand guidelines were unusually strict, and for good reason: never use technical language with patients. Their whole positioning rests on continuous human care. "You are talking to an AI" reads, in that context, like the care just got cheaper.

Both rules were correct. Neither was negotiable.

And both of the easy answers were wrong. Bury the disclosure in a footer nobody opens and you are technically compliant and actually deceptive. Lead with the technology — "Hi, I'm an AI assistant powered by…" — and you have handed a nervous patient a reason to distrust you before they have asked their first question.


How we resolved it

The declaration happens once, in the first message, in language a person actually reads. One sentence, no legal paragraph, no jargon: this is an assistant, it helps with first contact, a person from the team takes over from here.

Then the conversation goes back entirely to the client's voice. One honest sentence, then fifty warm ones.

A hand holding a phone where the first message in a conversation is in focus and the messages below fade out.
The disclosure belongs in the first message — designed in, not bolted on afterwards.

That is the whole trick, and it isn't much of a trick: compliance and brand voice only fight each other when the disclosure is treated as legal furniture added at the end. Written as the first line of the conversation — by whoever writes the rest of it — it stops being a warning and becomes an introduction.


What the AI Act actually asks of an ordinary business

Most coverage of the AI Act is written for large organisations building systems the law treats as high-risk: conformity assessments, technical documentation, registration, audits. If you are a business with 5–30 staff putting an assistant in front of customers, almost none of that is about you.

The obligation that actually bites is transparency. If people interact with an automated system, they have to know that. Not in a policy page — in the interaction itself.

This post is not about high-risk classification, conformity assessment or product certification. Those regimes exist, they matter to some businesses, and a customer-service assistant is not usually one of them. Worth knowing: recruitment and employee-assessment tools are one of the categories the law treats as high-risk, so if your automation reaches into hiring decisions, the heavier rules do apply to you.


The dates, correctly

This is where a lot of published advice is out of date, because the framework was amended in 2026.

  • GDPR (and UK GDPR) applies now, and always did. Lawful basis, transparency, retention, where the conversation is stored — none of that waited for an AI law.
  • Transparency obligations under the AI Act took effect on 2 August 2026, as originally scheduled. They were not postponed. If you run something conversational in front of EU customers today, this applies today.
  • One narrow easing: systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking of AI-generated content and deepfake labelling. That grace period does not cover telling people they are talking to an assistant.
  • High-risk obligations were deferred: the use-based category — including recruitment and employment tools — moves to 2 December 2027, and AI built into regulated products moves to 2 August 2028. This is a chance to get ahead of it, not an emergency.

If you are a UK business serving UK customers, the EU AI Act does not bind you. It reaches you only if you serve customers in the EU or your system's output is used there. What binds you is UK GDPR, and the ICO's expectations on fairness and transparency are close enough in spirit that the same design choices hold.


What this means practically

If your business runs anything that talks to customers automatically — website chat, a WhatsApp assistant, a voice agent, automated replies to enquiries — then four things need to be true:

  1. It discloses what it is, once, up front, in plain language a person reads without effort.
  2. It never claims to be human. If someone asks directly, the answer is straight.
  3. A human route stays open. "Talk to someone" is always available, and it works.
  4. You know what it must refuse. Written down, before launch, not discovered in a complaint.

The honest part: the disclosure was the easy bit

One sentence in the first message took an afternoon of wording. The hard part of that build was deciding what the assistant must never do.

For a health programme, that list is long and it is the actual work: no interpreting results, no adjusting anything a clinician set, no reassuring anyone about a symptom, no answering a question that sounds administrative but isn't. The assistant handles first contact and routes to a person — it does not stand in for the medical team, and every boundary we wrote existed to keep that order intact. A capable assistant is easy to build. A well-bounded one is where the weeks go.

And the finding that surprised us, worth stating plainly: declaring it up front didn't cost trust. It bought it. People relax when they know what they are talking to. The suspicion isn't caused by the assistant — it's caused by not being sure.


Five questions before you put an assistant in front of customers

  1. Does it say what it is — in the conversation, in the first message?
  2. Can a person take over, and does that route actually work?
  3. What does it refuse to do, and is that written down?
  4. Where does the conversation data live, and who else can see it?
  5. Who is accountable when it gets something wrong?

The fourth question has its own guide: Is it safe to give your customer data to an AI? · What is an AI agent, actually? · What to look for in an AI automation agency · AI automation services — managed roles


Frequently asked questions

Does my chatbot have to say it's AI?

If it holds a conversation with people in the EU, yes. The AI Act's transparency obligation requires that people know they are interacting with an automated system, and that information belongs in the interaction itself — practically, the first message — not only in a privacy policy.

When did the EU AI Act transparency rules start applying?

On 2 August 2026, as originally scheduled. They were not postponed by the 2026 amendments. Systems already on the market before that date have until 2 December 2026 for the separate duty to mark AI-generated content and label deepfakes.

Does the EU AI Act apply to a UK business?

Not directly. A UK business is covered only if it places an AI system on the EU market or its output is used by people in the EU. A UK company serving UK customers is governed by UK GDPR and the ICO's guidance, not by the EU AI Act.

Is my customer-service assistant a high-risk AI system?

Usually not. High-risk categories cover things like recruitment and employee assessment, credit scoring, education, and AI embedded in regulated products. A customer-service or booking assistant typically only carries the transparency obligation — but if your automation touches hiring decisions, the high-risk rules do apply.

What should an AI assistant disclose to customers?

That it is an automated assistant, what it can help with, and how to reach a person. One plain sentence up front is enough; a legal paragraph is worse, because nobody reads it.

Who is responsible when an AI assistant gets something wrong?

The business deploying it. Both under data-protection law and in practice, accountability sits with the deployer — which is why written boundaries and a working escalation path to a human matter more than the assistant's capabilities.


Not sure what your assistant would have to disclose?

Book a free 30-minute problem audit, or send the details asynchronously and get a free AI Automation Opportunity Report. We'll tell you honestly whether an agent fits the process at all, what it would have to disclose, and what it should refuse to do.

References: European Commission — AI Act regulatory framework (digital-strategy.ec.europa.eu), AI Omnibus in force 27 July 2026; ICO guidance on AI and data protection (ico.org.uk). This is a practical summary, not legal advice.