If you are building a chatbot or AI assistant and have EU users, the question "is this high-risk?" usually has a reassuring answer: no. Most conversational AI products, customer support bots, sales assistants, FAQ helpers, sit in the limited-risk tier under Article 50 of the EU AI Act, where the only mandatory obligation is telling users they are talking to AI.
But a small number of common product decisions quietly move a chatbot out of that comfortable tier and into the much heavier high-risk regime under Annex III. Founders who assume "it's just a chatbot" sometimes miss this until a customer, investor, or regulator asks the wrong question at the wrong time.
The default case: limited risk
A chatbot that answers product questions, helps with order status, walks a user through onboarding, or recommends products based on browsing history is doing exactly what Article 50 anticipates: interacting with a person without making decisions that materially affect their legal rights or access to services. The obligation here is straightforward:
- Tell the user, clearly and at the point of interaction, that they are talking to an AI system
- Do not bury that disclosure only in your Terms of Service
- If the bot generates images, audio, or video, label that content as AI-generated where technically feasible
That's it. No conformity assessment, no technical documentation file, no EU database registration.
The five situations that flip the classification
The AI Act classifies by function, not by product category. The same underlying LLM-powered chatbot architecture can be limited-risk in one deployment and high-risk in another, depending on what it actually decides. Watch for these:
- Recruitment screening. If your chatbot asks candidates questions and its output feeds into a shortlisting, ranking, or rejection decision, even as one input among several, you are in Annex III employment territory.
- Credit or insurance triage. A chatbot that collects financial information and its assessment influences a credit decision, loan approval, or insurance premium is high-risk, not limited-risk.
- Healthcare symptom triage. Bots that recommend a course of action based on symptoms, even informally, brush up against the medical high-risk category, particularly if the output is treated as diagnostic guidance rather than general information.
- Access to essential services. If your chatbot's assessment determines whether someone qualifies for a service, a benefit, or a tier of access, that is a decision with legal or similarly significant effect, the exact phrase the regulation uses to describe high-risk impact.
- Biometric elements. A voice assistant that performs voice-based identification or a visual chatbot that scans faces to personalise responses introduces biometric processing, which raises the risk classification independent of the conversational interface.
A quick test before you ship
Ask this question about your chatbot's output: does it influence, even partially, a decision about someone's job, credit, insurance, health treatment, education, or access to an essential service? If the honest answer is yes, treat the product as high-risk and start the compliance work (technical documentation, human oversight, conformity assessment) before launch, not after a complaint.
If the answer is genuinely no, your obligation is the Article 50 disclosure, and you can move on. The mistake to avoid is assuming the category by product type ("it's a chatbot, so it's fine") rather than checking the actual decision it makes.
EuroComply's free EU AI Act assessment asks the specific questions needed to make this call: what your system does, what sector it touches, and whether its output affects a person's rights. It takes about 3 minutes and returns a definitive risk tier along with the documents that tier requires.