News

AI Act 2026: Fines Up to €35M, Is Your Chatbot Compliant? (Complete Checklist)

September 8, 2026
22 min read
Ailog Team

The EU AI Act enters full enforcement in August 2026. Discover the penalties (up to €35M), obligations for chatbots and RAG systems, and our complete compliance checklist.

AI Act 2026: Fines Up to €35M, Is Your Chatbot Compliant?

The time for anticipation is over. On August 2, 2026, the EU AI Act enters full enforcement. For companies deploying AI chatbots, RAG assistants, or conversational AI systems, the implications are massive: fines of up to €35 million or 7% of global annual turnover.

TL;DR

  • The AI Act fully applies on August 2, 2026 -- chatbots are mainly classified as "limited risk" (transparency obligations)
  • Fines: up to €35M/7% turnover for prohibited practices, €15M/3% for high-risk obligations, €7.5M/1% for misinformation
  • Key obligation: inform users they are interacting with an AI
  • Finland is the first country to activate its national supervisory authority (January 2026)
  • The Digital Omnibus, adopted in June 2026, postpones high-risk obligations to December 2, 2027 (standalone Annex III systems) and August 2, 2028 (Annex I), but not chatbot transparency obligations
  • RAG platforms hosted in France (like Ailog) are natively better positioned for compliance

Complete AI Act Timeline

Key Dates to Remember

The AI Act did not enter into force all at once. The regulation follows a phased implementation since its adoption:

DateEventImpact
July 12, 2024Publication in EU Official JournalCountdown begins
August 1, 2024Official entry into forceTransition period starts
February 2, 2025Prohibition of banned practicesSubliminal manipulation, social scoring, exploitation of vulnerabilities
August 2, 2025Obligations for GPAI modelsTransparency, technical documentation, copyright compliance
January 2026Finland: first national authority activatedFirst country to supervise AI
August 2, 2026Full enforcementAll obligations, sanctions activated
December 2, 2027High-risk obligations (Annex III) -- postponed by the Digital OmnibusConfirmed deferral (Omnibus adopted June 2026)

What Is Already in Force

Since February 2, 2025, prohibited AI practices are already banned in Europe:

  • Subliminal manipulation: techniques that exploit psychological vulnerabilities
  • Social scoring: classifying people based on their social behavior
  • Predictive policing: individual profiling based solely on personal characteristics
  • Untargeted facial scraping: mass extraction of facial images from the internet

Since August 2, 2025, general-purpose AI models (GPAI) must comply with transparency and documentation obligations.


Risk Classification: Where Does Your Chatbot Fit?

The 4 Risk Levels of the AI Act

The AI Act classifies AI systems into four risk categories, each with specific obligations:

Risk LevelDescriptionExamplesObligations
UnacceptableProhibited practicesSubliminal manipulation, social scoringTotal prohibition
High riskCritical systemsAI recruitment, credit scoring, medical diagnosisFull compliance, audit, CE marking
Limited riskTransparency requiredChatbots, AI assistants, deepfakesDisclosure obligation
Minimal riskNo obligationAnti-spam filters, video game AINo specific obligation

Chatbots and RAG Systems: Limited Risk

The good news for companies deploying AI chatbots: most chatbots and RAG systems are classified as limited risk. This means obligations primarily focused on transparency.

Concrete obligations for chatbots (Article 50):

  1. AI disclosure: clearly inform the user they are interacting with an AI system
  2. Generated content marking: if the chatbot generates text, images, or audio, it must be identifiable as AI-generated
  3. Limitation information: the user must understand the system's capabilities and limitations

Possible exceptions toward high risk:

Certain chatbots may shift to high risk if:

  • They are used in recruitment (automated CV screening)
  • They make decisions affecting access to essential services
  • They are deployed in healthcare for diagnosis
  • They interact with critical infrastructure

Detailed Sanctions

Fine Structure

The AI Act provides for a progressive and dissuasive fine system:

Type of InfringementMaximum Fine% of Global TurnoverExample
Prohibited practices€35,000,0007%Chatbot with subliminal manipulation
High-risk obligations€15,000,0003%Non-compliant high-risk system
Misinformation / false declaration€7,500,0001%False statements to authorities

For SMEs and startups, fines are capped at the percentage of global turnover, which is proportionally more lenient.

AI Act vs GDPR Comparison

CriteriaAI ActGDPR
Maximum fine€35M or 7% turnover€20M or 4% turnover
ScopeAI systems in the EUPersonal data in the EU
ApproachRisk-basedRights-based
CE markingYes (high risk)No
DPO equivalentNot mandatory (but recommended)DPO mandatory in some cases
Impact assessmentMandatory (high risk)DPIA mandatory if high risk
CumulationYes, both applyYes, both apply

Crucial point: both regulations are cumulative. A chatbot must comply with both GDPR and the AI Act. To learn more about GDPR compliance for chatbots, see our GDPR and AI chatbots guide.

Enforcement Status in Early 2026

As of March 2026, no major enforcement action has been taken under the AI Act. National authorities are still being established in most Member States.

Finland is a pioneer, having activated its national supervisory authority in January 2026, demonstrating a proactive approach to enforcement.


Compliance Checklist for Chatbots and RAG Systems

1. Transparency (mandatory for all chatbots)

✅ User is informed they are interacting with an AI
✅ A clear message is displayed before/during interaction
✅ System limitations are documented
✅ AI-generated content is identified as such
✅ Response sources are traceable (RAG systems)

Implementation example:

DEVELOPERhtml
<!-- Transparency message in a chatbot widget --> <div class="ai-disclosure"> 🤖 You are chatting with an AI assistant powered by a knowledge base. Responses are automatically generated and may contain inaccuracies. </div>

2. Data Governance

✅ Training/indexing data is documented
✅ A conversation retention policy exists
✅ Personal data is processed in compliance with GDPR
✅ Hosting is identified and documented
✅ Transfers outside the EU are regulated (or non-existent)

3. Human Oversight

✅ A human escalation mechanism exists
✅ Operators can stop/modify the system
✅ Problematic conversations are flagged
✅ A regular review process is in place
✅ Users can request to speak with a human

4. Technical Documentation

✅ The system's general operation is documented
✅ Models used are identified
✅ Risk mitigation measures are described
✅ An incident register is maintained
✅ Performance and bias tests are documented

5. Risk Assessment

✅ The system's risk level is identified
✅ High-risk use cases are excluded or managed
✅ An impact assessment is performed if necessary
✅ Potential biases are identified and mitigated
✅ A continuous compliance plan is established

The Digital Omnibus: A Possible Reprieve?

The Digital Omnibus, given final approval by the Council of the EU on June 29, 2026 (following the European Parliament's endorsement on June 16, 2026), modifies the AI Act's enforcement timeline for certain categories:

  • Postponement of high-risk obligations: to December 2, 2027 for standalone Annex III systems, and to August 2, 2028 for AI embedded in regulated products (Annex I)
  • Relief for SMEs on certain documentation requirements
  • Clarification of high-risk classification criteria

However, transparency obligations for chatbots (limited risk, Article 50) and enforcement powers are not affected by these postponements: they remain applicable on August 2, 2026. Prudence therefore dictates preparing for that date.


Impact on the Chatbot Industry

Winners and Losers

ProfileImpactWhy
EU-hosted platforms✅ PositiveNative compliance, no data transfer
Transparent RAG solutions✅ PositiveSource traceability already built in
E-commerce chatbots⚠️ ModerateLimited risk, manageable obligations
AI recruitment tools❌ High impactLikely high-risk classification
US solutions without EU presence❌ High impactData transfers, complex compliance

European Competitive Advantage

The AI Act paradoxically creates a competitive advantage for European solutions:

  1. Native compliance: no need to adapt after the fact
  2. Sovereign hosting: no transatlantic data transfers to manage
  3. Customer trust: the "AI Act compliant" label becomes a sales argument
  4. Anticipation: European companies have had time to prepare

To learn more about the advantages of sovereign hosting, see our article on French sovereign RAG.


How Ailog Ensures Compliance

Architecture Designed for Compliance

Ailog was designed from the ground up with European compliance as a priority:

AI Act RequirementAilog Solution
Transparency"AI" badge displayed by default in widget, configurable message
TraceabilityEach response cites its sources (native RAG architecture)
FR hostingServers in France, no transfers outside the EU
Human oversightBuilt-in human agent escalation
Data governanceData siloed by organization, deletion on request
DocumentationComplete logs, audit trail, analytics dashboard

Simultaneous GDPR + AI Act Compliance

Ailog's approach covers both regulations:

GDPR                          AI Act
├── Consent                   ├── AI Transparency
├── Right to erasure          ├── Source Traceability
├── Portability               ├── Technical Documentation
├── Minimization              ├── Data Governance
└── EU Hosting                └── Human Oversight
         │                              │
         └──────── Ailog ───────────────┘
              Unified Compliance

To learn more about the AI Act's implications specifically for RAG systems, see our detailed AI Act and RAG guide.


5-Step Action Plan

To Be Ready Before August 2026

Step 1: Audit (month 1)

  • Inventory all deployed AI systems
  • Classify each system according to risk levels
  • Identify gaps with requirements

Step 2: Transparency (month 2)

  • Implement AI disclosure messages
  • Document each system's capabilities and limitations
  • Inform existing users

Step 3: Governance (months 2-3)

  • Document data flows
  • Implement retention policies
  • Verify hosting compliance

Step 4: Oversight (month 3)

  • Implement human escalation mechanisms
  • Train teams on AI system supervision
  • Set up review processes

Step 5: Documentation (month 4)

  • Write complete technical documentation
  • Set up incident register
  • Plan regular audits

FAQ

No. Most customer support, e-commerce, or documentation chatbots are indeed classified as limited risk. However, a chatbot used in recruitment (CV screening), healthcare (diagnosis), or for decisions affecting access to essential services may be classified as **high risk**, with much heavier obligations.
Yes. Like the GDPR, the AI Act has extraterritorial scope. It applies to any provider or deployer of AI systems whose users are in the EU, regardless of where the company is headquartered. A US company selling a chatbot to European customers is subject to the AI Act.
Article 50 of the AI Act requires that people interacting with an AI system are informed of this interaction. Concretely, this means a clear, visible, and understandable message before or at the beginning of the interaction. A simple "AI" badge or a welcome message mentioning AI is sufficient.
No. The Digital Omnibus, adopted in June 2026, provides for timeline adjustments (postponement of high-risk obligations) and relief for SMEs, but does not challenge the fundamental transparency obligations for chatbots. Limited risk obligations (AI disclosure) will remain applicable, potentially with some clarifications.
There is no official "AI Act compliant" certification yet for limited-risk systems. However, documenting your approach (transparency, governance, oversight) in a compliance file is strongly recommended. For high-risk systems, CE marking and audits will be required. ---

Conclusion

The AI Act is not a threat -- it is an opportunity to professionalize the AI chatbot industry. Companies that prepare now will have a major competitive advantage: their customers' trust and native compliance.

Platforms like Ailog, designed from the start with European compliance in mind -- French hosting, source transparency, human oversight -- are naturally positioned for this transition.

Don't wait until August 2026 to act. Create your Ailog account and deploy a compliant AI chatbot today.


This article is provided for informational purposes only and does not constitute legal advice. Consult a specialized lawyer for your specific situation.

Tags

AI ActAI regulationcompliancechatbotGDPREurope

Related Posts

Ailog Assistant

Ici pour vous aider

Salut ! Pose-moi des questions sur Ailog et comment intégrer votre RAG dans vos projets !