Your chatbot has to say it's AI. From 28 October a regulator checks
September 7, 2026

If there's a chatbot on your site or an AI assistant answering your phone, you've had a new obligation since 2 August 2026. Not 2027. Not "at some point." Since August.
Most companies missed it, because the headline that week said something else entirely: "the EU delayed the AI Act." That's true, and it's about a different part of the law. The part covering your bot arrived on schedule. And from 28 October 2026, a national authority in Poland can fine you for breaking it.
This is an implementation guide, not legal advice. What to change in the bot, in what order, and where the traps are that we see at clients.
What has to happen in the first second of the conversation
Article 50 of Regulation (EU) 2024/1689 says something simple: a person interacting with an AI system has to know it. The information must arrive at the latest at the first interaction, clearly and in a way that stands out.
Three practical consequences:
The disclosure goes at the start, not the end. Not in the terms of service, not in the privacy policy, not behind a small "i" icon. The first chat message and the first sentence of the call.
It has to be readable by a human, not a lawyer. "This service utilises solutions based on artificial intelligence" is a sentence written so nobody reads it. "Hi, I'm an AI assistant" discharges the same obligation without sounding like a debt collection notice.
It covers voice too. A phone assistant is a system intended for direct interaction with a natural person — the same rule, only harder technically, because there's nowhere to tuck a discreet footnote.
The second obligation in the same article covers machine-generated content: it has to be marked in a machine-readable format. There's a transition period here — systems already on the market before 2 August 2026 have until 2 December 2026.
"It's obviously a bot" — why that exemption rarely saves you
The rule has an exemption: no disclosure needed where it is obvious to a reasonably well-informed person. The European Commission reads that exemption narrowly in its guidelines of 20 July 2026.
And here's the paradox worth understanding before you lean on it: the better your system, the less right you have to the exemption. A widget with three fixed buttons is obvious. A voice agent that sounds human, interrupts naturally and answers a question asked mid-sentence is the opposite of obvious. We build them that way on purpose, so people don't hang up.
If anyone mistook your bot for a person in the last year, the exemption won't cover you.
The calendar that actually applies to you
Two things landed in the summer of 2026 at once, which is where the confusion comes from. The EU Digital Omnibus (in force since 27 July 2026) genuinely did postpone obligations for high-risk systems. It did not touch Article 50.
| Date | What happens | Status |
|---|---|---|
| 2 August 2026 | Duty to disclose AI interaction (Article 50) | In force |
| 11 August 2026 | Main provisions of the Polish AI systems act enter into force | In force |
| 28 October 2026 | KRiBSI: inspections, proceedings, administrative fines | Imminent |
| 2 December 2026 | End of transition for marking AI-generated content | Imminent |
| 2 December 2027 | High-risk systems under Annex III | Postponed |
| 2 August 2028 | High-risk systems under Annex I | Postponed |
If someone told you in the summer that "the AI Act got pushed to 2027," they were describing the last two rows of that table. Not the first one.
KRiBSI: who they are and what they can do
Poland's AI systems act was published in the Journal of Laws on 27 July 2026. It creates the Commission for the Development and Safety of Artificial Intelligence — the national market surveillance authority and single point of contact. The acronym worth remembering: KRiBSI.
From 28 October 2026, the rules on inspections, proceedings before the authority, settlements reducing penalties, and administrative fines start to apply. The maximum thresholds come straight from the regulation:
- up to EUR 35M or 7% of worldwide turnover — prohibited practices
- up to EUR 15M or 3% of turnover — including breaches of Article 50 transparency duties
- up to EUR 7.5M or 1% of turnover — other breaches
For small and mid-sized companies, the lower of the two values applies, which for most readers of this blog means a percentage, not millions of euros. It still hurts. But let's stop frightening the corner hair salon with a EUR 15M fine, because it isn't true and nobody believes it.
The same act offers something few people mention: you can ask KRiBSI for an individual opinion. If you have an unusual setup and genuinely don't know which side of the line you're on, that's cheaper than a dispute after an inspection.
Provider or deployer — this decides how much work you have
This distinction sets the scope of your obligations and is the most common source of mistakes. We covered it at length in our piece on what the AI Act means for a company; here's the operational summary.
The duty to design the system so that it announces its own nature sits with the provider. Buy an off-the-shelf chat widget and paste it on your site, and the provider is the vendor — your job is mainly not to switch off what they prepared. And to check they prepared it at all.
Commission an assistant under your own brand, with its own name and personality, and the situation changes. Putting your brand on a system can push you toward the provider role. This isn't a lawyer's nuance: it's the difference between "check one setting in a panel" and "you are responsible for the design of the system."
If your bot has a name, its own voice, and nobody on the site could name the vendor — treat yourself as the provider until a lawyer says otherwise.
What this looks like in a voice agent
Here's the part you won't find in law firm analyses, because it takes a deployment rather than a reading.
When we build a voice assistant for a company, the identifying sentence is part of the first utterance — before it asks what the caller needs. Not after. The order matters practically, not just formally: a caller who learns about the AI after explaining their whole problem feels tricked. The same message at the start is neutral.
Three things we check at every launch:
- The identifying sentence lives in the greeting, not the fallback script. Common mistake: the disclosure sits in the "what to do if the caller asks whether this is a human" branch. Since most callers never ask, in most calls it simply never gets said.
- Handover to a human doesn't wipe the context. The caller has to be able to say "I want to speak to a person" and get transferred. That isn't an Article 50 requirement, but it is the difference between a system people tolerate and one that generates complaints — and a complaint to the regulator is the shortest route to an inspection.
- Channels other than the phone have their own greeting. A form, a website chat and an auto-reply are separate first-interaction points. A company handling a few thousand calls a month usually has three or four of them and secures one.
The most common real problem isn't legal, it's organisational: the bot was deployed by someone who has left the company, and nobody knows where the greeting is edited. Before you start reading the regulation, check whether you have access to the panel.
What a sentence that does the job sounds like
The obligation is discharged with one phrase. The problem is most companies write it as though they were paying by the word.
| Channel | Works | Doesn't work |
|---|---|---|
| Phone | "Hi, this is Anna, the AI assistant at reception. How can I help?" | "This call may be handled by automated systems" |
| Website chat | "Hi, I'm an AI assistant. I'll answer questions or pass you to the team." | Disclosure in the widget footer, under an "i" icon |
| Auto-reply | "This reply was prepared by an AI assistant." | No marking at all, because "it's just an autoresponder" |
The rule we apply: the disclosure has to fit inside a natural greeting without changing its rhythm. A sentence that reads like a legal disclaimer gets ignored exactly like no sentence at all — except that at an inspection you formally have it. The goal is for the caller to actually know, not for it to be provable.
If the agent has a name, keep it. "I'm Anna, an AI assistant" works better than an impersonal "this is an automated system" — the caller gets a reference point and tests the machine less.
A 30-minute checklist
You don't need an audit or a law firm for this. You need a phone and a browser.
- Call your own line and listen to the first sentence. Does it say you're talking to AI?
- Open your site in a private window and type "hello" into the chat. Check the first reply, not the third.
- Check automated email replies and social media messages, if AI generates them.
- Establish who has edit access to the greeting on each channel. Write it down.
- If you publish machine-generated content, you have until 2 December 2026 to mark it.
- Put 28 October 2026 in the calendar. Not because something is due that day, but so it's done before it.
If every point comes back green, you don't have a problem and can go back to work. If not, fixing a greeting is usually a matter of minutes in a panel, not a deployment project.
What this regulation does not require
There's a lot of fear circulating, so for the record — as of today, for a typical company using a bot for customer service:
- You don't have to register your chatbot anywhere.
- You don't need a conformity assessment or CE marking. That's the high-risk path, and customer service generally doesn't land there.
- You don't have to drop AI from customer service or hide that you use it. The rule requires exactly the opposite move.
- You don't need an appointed AI officer.
The overwhelming majority of the obligations that sounded alarming in the press apply to high-risk systems — recruitment, employee assessment, scoring, critical infrastructure. If you use AI to book appointments and answer questions about opening hours, your task list ends at one sentence in the greeting.
What follows from this
This regulation doesn't add work. It forces something that was worth doing anyway — because a customer who realises halfway through the call that they're talking to a machine calls back with a complaint regardless. The difference is that from 28 October that complaint has an address to go to.
If you're planning an agent deployment in the coming months, build it so the topic never comes back. If you've had a bot for two years and don't know what it says in its first sentence — check today, it takes three minutes.
Want someone to walk your channels with you? Book a free consultation — we'll show you where you actually stand and what needs fixing. If you're still weighing a deployment, start with AI agents for business and AI implementation step by step.
Sources:
- Transparency obligations under Article 50 AI Act — FAQ, European Commission
- Commission guidelines on transparency obligations (20 July 2026)
- The AI systems act — Polish Ministry of Digital Affairs
- Government bill on artificial intelligence systems (print 2443) — Sejm of the Republic of Poland
This text describes the position as at 7 September 2026 and is not legal advice. For an unusual system configuration, confirm the role classification with a lawyer or request an individual opinion from the authority.
