AI Act 2026: Fines Up to €35M, Is Your Chatbot Compliant? (Complete Checklist)
The EU AI Act enters full enforcement in August 2026. Discover the penalties (up to €35M), obligations for chatbots and RAG systems, and our complete compliance checklist.
AI Act 2026: Fines Up to €35M, Is Your Chatbot Compliant?
The time for anticipation is over. On August 2, 2026, the EU AI Act enters full enforcement. For companies deploying AI chatbots, RAG assistants, or conversational AI systems, the implications are massive: fines of up to €35 million or 7% of global annual turnover.
TL;DR
- The AI Act fully applies on August 2, 2026 -- chatbots are mainly classified as "limited risk" (transparency obligations)
- Fines: up to €35M/7% turnover for prohibited practices, €15M/3% for high-risk obligations, €7.5M/1% for misinformation
- Key obligation: inform users they are interacting with an AI
- Finland is the first country to activate its national supervisory authority (January 2026)
- The Digital Omnibus, adopted in June 2026, postpones high-risk obligations to December 2, 2027 (standalone Annex III systems) and August 2, 2028 (Annex I), but not chatbot transparency obligations
- RAG platforms hosted in France (like Ailog) are natively better positioned for compliance
Complete AI Act Timeline
Key Dates to Remember
The AI Act did not enter into force all at once. The regulation follows a phased implementation since its adoption:
| Date | Event | Impact |
|---|---|---|
| July 12, 2024 | Publication in EU Official Journal | Countdown begins |
| August 1, 2024 | Official entry into force | Transition period starts |
| February 2, 2025 | Prohibition of banned practices | Subliminal manipulation, social scoring, exploitation of vulnerabilities |
| August 2, 2025 | Obligations for GPAI models | Transparency, technical documentation, copyright compliance |
| January 2026 | Finland: first national authority activated | First country to supervise AI |
| August 2, 2026 | Full enforcement | All obligations, sanctions activated |
| December 2, 2027 | High-risk obligations (Annex III) -- postponed by the Digital Omnibus | Confirmed deferral (Omnibus adopted June 2026) |
What Is Already in Force
Since February 2, 2025, prohibited AI practices are already banned in Europe:
- Subliminal manipulation: techniques that exploit psychological vulnerabilities
- Social scoring: classifying people based on their social behavior
- Predictive policing: individual profiling based solely on personal characteristics
- Untargeted facial scraping: mass extraction of facial images from the internet
Since August 2, 2025, general-purpose AI models (GPAI) must comply with transparency and documentation obligations.
Risk Classification: Where Does Your Chatbot Fit?
The 4 Risk Levels of the AI Act
The AI Act classifies AI systems into four risk categories, each with specific obligations:
| Risk Level | Description | Examples | Obligations |
|---|---|---|---|
| Unacceptable | Prohibited practices | Subliminal manipulation, social scoring | Total prohibition |
| High risk | Critical systems | AI recruitment, credit scoring, medical diagnosis | Full compliance, audit, CE marking |
| Limited risk | Transparency required | Chatbots, AI assistants, deepfakes | Disclosure obligation |
| Minimal risk | No obligation | Anti-spam filters, video game AI | No specific obligation |
Chatbots and RAG Systems: Limited Risk
The good news for companies deploying AI chatbots: most chatbots and RAG systems are classified as limited risk. This means obligations primarily focused on transparency.
Concrete obligations for chatbots (Article 50):
- AI disclosure: clearly inform the user they are interacting with an AI system
- Generated content marking: if the chatbot generates text, images, or audio, it must be identifiable as AI-generated
- Limitation information: the user must understand the system's capabilities and limitations
Possible exceptions toward high risk:
Certain chatbots may shift to high risk if:
- They are used in recruitment (automated CV screening)
- They make decisions affecting access to essential services
- They are deployed in healthcare for diagnosis
- They interact with critical infrastructure
Detailed Sanctions
Fine Structure
The AI Act provides for a progressive and dissuasive fine system:
| Type of Infringement | Maximum Fine | % of Global Turnover | Example |
|---|---|---|---|
| Prohibited practices | €35,000,000 | 7% | Chatbot with subliminal manipulation |
| High-risk obligations | €15,000,000 | 3% | Non-compliant high-risk system |
| Misinformation / false declaration | €7,500,000 | 1% | False statements to authorities |
For SMEs and startups, fines are capped at the percentage of global turnover, which is proportionally more lenient.
AI Act vs GDPR Comparison
| Criteria | AI Act | GDPR |
|---|---|---|
| Maximum fine | €35M or 7% turnover | €20M or 4% turnover |
| Scope | AI systems in the EU | Personal data in the EU |
| Approach | Risk-based | Rights-based |
| CE marking | Yes (high risk) | No |
| DPO equivalent | Not mandatory (but recommended) | DPO mandatory in some cases |
| Impact assessment | Mandatory (high risk) | DPIA mandatory if high risk |
| Cumulation | Yes, both apply | Yes, both apply |
Crucial point: both regulations are cumulative. A chatbot must comply with both GDPR and the AI Act. To learn more about GDPR compliance for chatbots, see our GDPR and AI chatbots guide.
Enforcement Status in Early 2026
As of March 2026, no major enforcement action has been taken under the AI Act. National authorities are still being established in most Member States.
Finland is a pioneer, having activated its national supervisory authority in January 2026, demonstrating a proactive approach to enforcement.
Compliance Checklist for Chatbots and RAG Systems
1. Transparency (mandatory for all chatbots)
✅ User is informed they are interacting with an AI
✅ A clear message is displayed before/during interaction
✅ System limitations are documented
✅ AI-generated content is identified as such
✅ Response sources are traceable (RAG systems)
Implementation example:
DEVELOPERhtml<!-- Transparency message in a chatbot widget --> <div class="ai-disclosure"> 🤖 You are chatting with an AI assistant powered by a knowledge base. Responses are automatically generated and may contain inaccuracies. </div>
2. Data Governance
✅ Training/indexing data is documented
✅ A conversation retention policy exists
✅ Personal data is processed in compliance with GDPR
✅ Hosting is identified and documented
✅ Transfers outside the EU are regulated (or non-existent)
3. Human Oversight
✅ A human escalation mechanism exists
✅ Operators can stop/modify the system
✅ Problematic conversations are flagged
✅ A regular review process is in place
✅ Users can request to speak with a human
4. Technical Documentation
✅ The system's general operation is documented
✅ Models used are identified
✅ Risk mitigation measures are described
✅ An incident register is maintained
✅ Performance and bias tests are documented
5. Risk Assessment
✅ The system's risk level is identified
✅ High-risk use cases are excluded or managed
✅ An impact assessment is performed if necessary
✅ Potential biases are identified and mitigated
✅ A continuous compliance plan is established
The Digital Omnibus: A Possible Reprieve?
The Digital Omnibus, given final approval by the Council of the EU on June 29, 2026 (following the European Parliament's endorsement on June 16, 2026), modifies the AI Act's enforcement timeline for certain categories:
- Postponement of high-risk obligations: to December 2, 2027 for standalone Annex III systems, and to August 2, 2028 for AI embedded in regulated products (Annex I)
- Relief for SMEs on certain documentation requirements
- Clarification of high-risk classification criteria
However, transparency obligations for chatbots (limited risk, Article 50) and enforcement powers are not affected by these postponements: they remain applicable on August 2, 2026. Prudence therefore dictates preparing for that date.
Impact on the Chatbot Industry
Winners and Losers
| Profile | Impact | Why |
|---|---|---|
| EU-hosted platforms | ✅ Positive | Native compliance, no data transfer |
| Transparent RAG solutions | ✅ Positive | Source traceability already built in |
| E-commerce chatbots | ⚠️ Moderate | Limited risk, manageable obligations |
| AI recruitment tools | ❌ High impact | Likely high-risk classification |
| US solutions without EU presence | ❌ High impact | Data transfers, complex compliance |
European Competitive Advantage
The AI Act paradoxically creates a competitive advantage for European solutions:
- Native compliance: no need to adapt after the fact
- Sovereign hosting: no transatlantic data transfers to manage
- Customer trust: the "AI Act compliant" label becomes a sales argument
- Anticipation: European companies have had time to prepare
To learn more about the advantages of sovereign hosting, see our article on French sovereign RAG.
How Ailog Ensures Compliance
Architecture Designed for Compliance
Ailog was designed from the ground up with European compliance as a priority:
| AI Act Requirement | Ailog Solution |
|---|---|
| Transparency | "AI" badge displayed by default in widget, configurable message |
| Traceability | Each response cites its sources (native RAG architecture) |
| FR hosting | Servers in France, no transfers outside the EU |
| Human oversight | Built-in human agent escalation |
| Data governance | Data siloed by organization, deletion on request |
| Documentation | Complete logs, audit trail, analytics dashboard |
Simultaneous GDPR + AI Act Compliance
Ailog's approach covers both regulations:
GDPR AI Act
├── Consent ├── AI Transparency
├── Right to erasure ├── Source Traceability
├── Portability ├── Technical Documentation
├── Minimization ├── Data Governance
└── EU Hosting └── Human Oversight
│ │
└──────── Ailog ───────────────┘
Unified Compliance
To learn more about the AI Act's implications specifically for RAG systems, see our detailed AI Act and RAG guide.
5-Step Action Plan
To Be Ready Before August 2026
Step 1: Audit (month 1)
- Inventory all deployed AI systems
- Classify each system according to risk levels
- Identify gaps with requirements
Step 2: Transparency (month 2)
- Implement AI disclosure messages
- Document each system's capabilities and limitations
- Inform existing users
Step 3: Governance (months 2-3)
- Document data flows
- Implement retention policies
- Verify hosting compliance
Step 4: Oversight (month 3)
- Implement human escalation mechanisms
- Train teams on AI system supervision
- Set up review processes
Step 5: Documentation (month 4)
- Write complete technical documentation
- Set up incident register
- Plan regular audits
FAQ
Conclusion
The AI Act is not a threat -- it is an opportunity to professionalize the AI chatbot industry. Companies that prepare now will have a major competitive advantage: their customers' trust and native compliance.
Platforms like Ailog, designed from the start with European compliance in mind -- French hosting, source transparency, human oversight -- are naturally positioned for this transition.
Don't wait until August 2026 to act. Create your Ailog account and deploy a compliant AI chatbot today.
This article is provided for informational purposes only and does not constitute legal advice. Consult a specialized lawyer for your specific situation.
Tags
Related Posts
EU AI Act: Impact on RAG Systems
Understanding the AI Act and its implications for RAG systems. Risk classification, obligations, and compliance implementation.
GDPR and AI Chatbots: Complete Compliance Guide
How to make your AI chatbot GDPR compliant. Consent, user rights, data retention and best practices for conversational AI.
AI Chatbot for PrestaShop: RAG Integration Guide
Deploy an intelligent AI assistant on your PrestaShop store. Automate customer support, recommend products, and boost conversions with RAG technology.