AURA

AI Act and your chatbot: what a small business must do from 2 August 2026 and what comes later

From 2 August 2026, chatbots and AI systems must clearly inform users they are interacting with a machine. Check if your business meets the new transparency requirements and what's still ahead.

Published
16 min read3206 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • From 2 August 2026, chatbots and virtual assistants must introduce themselves as a machine — clearly and at first contact
  • RODO still applies alongside AI Act — it's not either/or
  • Unacceptable practice bans and competency requirements have been in force since 2 February 2025
  • High-risk systems (Annex III) will apply from 2 December 2027 — check if your AI qualifies
  • Ask your provider: how the system introduces itself, where logs are stored, how escalation to humans works

A few words that show up in this text

Explained in plain language — you do not need to know the trade to read on.

chatbot
A program that answers questions according to a ready-made scenario.
RODO
Polish name for the European GDPR data protection law.
follow-up
A planned return to the client after the first conversation or quote.
CRM
One place holding clients and enquiries: who asked, about what, and what happened next.
Google Business Profile
Company listing in Google and Maps.
lead
An enquiry from someone still considering a purchase — not a client yet.

If you have a chatbot on your website, use AI to answer phone calls, or respond to customers through messengers automatically — you need to know what changed. From 2 August 2026, the transparency requirements of the AI Act regulation start to apply, directly affecting such contact points — and some other provisions have already been in force for a while. In this article you'll find a specific calendar, a table of questions for your provider, and a "do it this evening" guide — without legal conclusions you'd need to consult a lawyer about.

First you'll do an inventory of your own AI contact points, then check which regulations already apply and which are coming later. You'll learn what the transparency obligation looks like in practice and where RODO fits in.

Brass reception bell on wooden counter with emerald glow
Customer reception zone — where AI can take over part of the interaction

Where in the company "the machine answers" — inventory of contact points

Before checking regulations, list all places where a customer communicates with a system, not a person. This includes any technology that answers, helps, or automates contact. You don't need technical details here — just identify the point and indicate who is responsible for its operation.

Most common AI contact points in a small service business:

Contact pointWho is responsibleNotes
Chat on websiteChatbot provider / companyUsually configuration is with the provider
AI answering phone (AI reception)Service providerYou can influence the conversation scenario
Auto-replies in WhatsApp / MessengerIntegration providerDepends on panel settings
Bot for generating text or images for adsTool (e.g., ChatGPT, Midjourney)User is responsible for usage method
Automated reminders and follow-upCRM or automation systemUsually company configuration

Go through all customer communication channels: website, phone, email, messengers, Google Business Profile. For each channel, ask yourself: "In this place, does the customer talk to a person or a system?" If to a system — add it to the table above. It takes 10–15 minutes and gives you a complete picture of the legal situation.

From 2 August 2026 — transparency obligation

This is the most important change for small business owners using chatbots and AI for customer service. From this day, transparency requirements from the AI Act apply. A person using an artificial intelligence system must be clearly informed that they are interacting with a machine — if it's not obvious from the context. This applies to chatbots, virtual assistants, and automated customer service systems, among others. The information should be provided at the latest at the first contact and in a clear, understandable, and accessible manner, including for people with special needs — according to the Ministry of Digital Affairs.

What does this mean in practice? The chatbot's first phrase on the website must clearly say that the customer is talking to an automation. In the case of AI answering the phone — the system must introduce itself as a machine no later than the first contact with the customer. It's not about using complex legal formulas — it's about the customer knowing from the first moment who they are dealing with.

What to write in the first phrase

The legal requirement is one thing: tell the customer they're talking to AI. It's good practice to also let them know they can reach a human if needed — that's not a legal obligation, but it's what actually builds trust. Keep it short and natural. A simple "I'm an automated assistant" works better than legal jargon. Add something like "I'll help with X, or you can ask to speak with a person" to cover the legal requirement and the good practice at once.

First phrase examples (as a template, not as a mandatory legal formula):

  • Chat on website: "Hi! I'm the automatic assistant of company X. I'll answer your questions, and if needed, I'll pass your case to the team."
  • Phone: "Good morning, this is the automatic assistant of company X. I can help with appointment booking, scheduling, and service information. How can I help you?"

These examples aren't ready legal formulas — they're a starting point. The template should be adapted to your company's tone and target audience. If you're unsure whether your current first phrase meets the requirements — check it yourself: after reading the first sentence, does the customer know they're talking to a machine? If not — time to change.

Marking AI-generated content

The AI Act also introduces requirements regarding content generated by artificial intelligence. This primarily concerns the obligation to mark content that could be misleading — realistic images, audio and video showing people, objects, places or events (deepfakes) created using AI that could be mistakenly considered authentic. This also covers a photorealistic "photo" of premises that don't actually exist. In the context of a small business, this means primarily caution when using visual and text advertising materials generated by AI.

If you generate images for advertising using tools like Midjourney, DALL-E, or others — you don't need to mark each of them with a visible "generated by AI" label. The requirement primarily concerns content that could be mistakenly taken for authentic recordings or statements of real people. Advertising graphics depicting your premises usually aren't such a case, unless you clearly suggest it's a photo of your premises when it's actually generated.

When to be cautious

The biggest risk is situations where the viewer might think they're seeing a real recording or statement of a real person. A video showing "your employee" advertising a service, but actually generated by AI — that's a case to think about. Same with voice: if AI speaks in the voice of a specific person without their consent, that's a problem. Regular advertising graphics showing your premises, product, or service in a stylized way — that's normal practice and doesn't require special marking.

Doubts about a specific case — for example, whether your advertising campaign needs additional marking — are worth consulting with a lawyer, because it depends on the specific context and presentation method.

What this means for your advertising

When you create promotional materials with AI tools, focus on whether the content could mislead customers about reality. A fictional illustration for your ad doesn't need disclosure. But if you pass an AI-generated image as a real photo of your salon or office, that's where problems start. Keep your marketing honest and transparent about what's real versus generated.

What already applies — from 2 February 2025

Not everything starts in August 2026. From 2 February 2025, provisions regarding unacceptable AI practices bans and requirements related to developing artificial intelligence competencies have been in force — according to the Ministry of Digital Affairs. What does this mean in practice for a small business?

Unacceptable practice bans concern AI systems that use psychological manipulation, exploit vulnerabilities of persons (e.g., children, elderly), categorise people based on biometric data, or apply social scoring. In practice for a typical small service business, these bans rather concern large platforms and state systems than a typical website chatbot or AI reception.

Competency requirements mean that people working with AI systems should have an appropriate level of knowledge and skills. For a small business owner, this simply means: if you use AI in your business — ensure that people responsible for customer contact understand how these tools work and what their limitations are. A simple memo for the team that "AI answers from the knowledge base, doesn't know details of a specific case, in case of doubt redirect to a person" — that's already a step in the right direction.

Hand resting on desk next to speaker with green indicator light
Human and machine at one desk — collaborating with AI

High-risk systems — what's been postponed

Provisions regarding high-risk systems listed in Annex III to the AI Act will apply from 2 December 2027 — according to the Ministry of Digital Affairs. This concerns specific AI applications in education, employment, access to basic services, justice, and migration, among others. For an average small service business, this means these regulations probably don't apply — unless you use AI for automatic candidate screening or for making decisions in the areas listed in Annex III (e.g., credit scoring, life and health insurance, recruitment, education).

If your AI only answers customer questions, schedules visits, and collects contacts — it's not a high-risk system under the AI Act. However, if you use AI to automatically decide whether a customer qualifies for your service, or to evaluate candidates — check if your cases fall under Annex III. When in doubt — consult a lawyer.

Additionally, AI systems in regulated products (e.g., medical devices, certified equipment) will be subject to regulations from 2 August 2028. This also typically doesn't apply to a typical small service business.

AI Act doesn't replace RODO

This is an important point that often raises doubts. The AI Act doesn't replace the General Data Protection Regulation or other privacy regulations. These provisions must be applied in parallel — according to the Ministry of Digital Affairs. If your chatbot collects name, phone, email, and problem description from a customer — RODO still applies to you. You need a legal basis for processing (usually consent or legitimate interest), you must have a privacy policy, and you must enable customers to exercise their rights (access, correction, deletion).

Where do personal data appear in chatbots and AI reception? Primarily in questions the customer asks (may contain name, phone, address, health or financial problem description), in conversation records (stored in system or CRM), in provider logs (where data physically lands — depends on provider and server location).

More about where your customer data physically ends up can be found in the article about automation and RODO.

Transferring to a human — how it should work

The law doesn't require handing the conversation off to a person — it only requires informing the customer that it's a machine. But from a good-customer-service point of view, it's worth offering that option, especially in a few situations:

  • Customer explicitly asks for a person ("I want to talk to a consultant", "transfer me to someone").
  • The case is too complicated for AI — for example, an unusual problem, complaint, legal matter.
  • Customer files a complaint — the automation shouldn't "process" the complaint on its own.

In practice, this means your system should have a simple escalation mechanism: a keyword ("person", "consultant", "transfer"), redirection after the customer's third message, or a clear "Talk to a person" button. This isn't regulated by law — but from the viewpoint of good customer service and minimizing legal risk, it's fundamental.

Who handles escalated cases? In a small business, it's usually the owner or the person responsible for customer contact. It's important that these hours are clearly defined and that the customer knows when they can expect a response. If human phone duty runs until 6 PM — inform about this in the first AI phrase: "If you want to talk to a person, they're available until 6 PM, otherwise you'll hear back tomorrow morning."

How many Polish businesses actually use AI — statistics

8.36%
According to Eurostat data for 2025, 8.36% of enterprises in Poland (with 10 or more employees) used at least one AI technology — for example, text analysis, speech recognition, chatbots, or autonomous robots.
20%
For comparison, the EU average is almost 20%, and leaders — Denmark (42.03%), Finland (37.82%), and Sweden (35.04%) — significantly lead.
5.21%
Poland is among the countries with the lowest rate, alongside Romania (5.21%) and Bulgaria (8.55%) — according to Eurostat.

This figure only covers enterprises with 10 or more employees — there's no comparable separate data for smaller service businesses like yours. Still, the result shows a clear trend: Poland is far behind the European average in AI implementation in business.

Talking to your provider — key issues to clarify

Before trusting a provider, check several key issues. It's not about quitting the service — it's about knowing what you're responsible for and what the provider is responsible for. Below is a table of questions worth asking:

QuestionGood answerAnswer that should raise alertness
How does the system introduce itself to customers?"The first phrase is configurable — we can set any greeting""It can't be changed" or no specific answer
Where are conversation logs stored?"Logs are on servers in Poland/EU, access only for authorized people from your company""We don't know" or "on our servers, but we won't say where"
Do you have a Data Processing Agreement (DPA)?"Yes, we'll send a template for signing before launch""That's not needed" or "the contract is in the terms"
How does transferring to a person work?"Customer writes 'person' or clicks the button — the case goes to the designated person with full conversation history""The automation answers everything"
Can I change the first phrase myself?"Yes, in the admin panel — I'll show you how""Only we can change it, additional cost"

You don't need to understand all technical details — but you should get specific answers. If the provider avoids answers or doesn't want to sign a data processing agreement — that's a warning sign.

More about the difference between AI agent and chatbot can be read in the article AI agent vs chatbot: the difference visible in three process characteristics. If you're interested in automation and RODO topics — see where customer data physically ends up. Also check process automation in a company to see what can realistically be handed over to a system.

Brass balance scale on dark background with stone and green bead
Balance between automation and responsibility

Do it this evening — practical checklist

Check your AI contact points in one evening. You don't need a lawyer or IT specialist for this — you need 30 minutes and this list:

  1. Go to your website and open the chat. What's the first phrase? Does it clearly say it's an automation? If not — note what needs to be changed.
  2. Call your phone number (preferably from another phone). How does the AI introduce itself? Does it say it's a machine? Note what you heard.
  3. Send a message on WhatsApp or Messenger to your company. What does the automatic response look like? Is it clear that a bot is answering?
  4. Check the escalation button: is there an option in the chatbot to "talk to a person"? Does it work?
  5. Assign a person responsible for checking these changes and set a deadline: when should the first phrase be corrected?

This isn't a full legal audit — it's a quick review that lets you orient whether the basics are in order. If after this review it turns out something needs changing — you'll know where to act.

How it looks in the system — integration with your workflow

This is what an ideally configured AI contact point looks like in a small service business.

  1. Customer message
  2. automated greeting
  3. answer from knowledge base
  4. hard case to a person
  5. logged in CRM
The diagram shows the same process step by step — from the first link to the last.

The first phrase says "I'm the automatic assistant of company X", the system answers from your knowledge base (schedule, prices, services, FAQ), and when the question is too complicated or the customer asks for a person, the case goes to the appropriate person in the company with the full conversation history saved in CRM, so they can continue with full context.

This is a model that meets AI Act transparency requirements and simultaneously really helps in business — frees you from answering simple questions about opening hours, prices, and availability, while not leaving the customer without help in more difficult matters.

If you want to see how such a system works in practice — check AI Chatbot, which answers from your knowledge base and introduces itself as AI from the first phrase. Or AI reception and telephony, which answers the phone, understands speech, and qualifies the inquiry. If you already have a system but want to improve it — Request automation will let you connect all channels into one. You also need CRM and automations to keep all data in one place. And if you want notifications in messengers — check Telegram / WhatsApp Integrations.

Frequently asked questions

Do I need to mark every AI-generated image in advertising?

Not every one. The marking obligation primarily concerns content that could be misleading about authenticity — for example, video or audio deepfakes representing real people. Regular advertising graphics generated by AI usually don't require special marking, unless you clearly suggest it's a photo of your premises when it's actually generated. When in doubt, consult a lawyer.

Does the chatbot on the website have to be in Polish?

AI Act regulations don't impose language — but you must ensure that information about the customer talking to a machine is communicated in a way understandable to the user. If your customers speak Polish — communication is obviously in Polish.

What if my provider doesn't want to sign a data processing agreement?

This is a serious warning sign. Without a DPA (Data Processing Agreement), you don't have a formal basis for processing customer data through that provider. Consider changing to a provider that offers a standard contract — or consult with a DPO.

Does AI Act apply to sole proprietorship?

Yes, but the roles differ. The information duty under Article 50(1) falls primarily on the provider of the AI system (e.g., the chatbot's maker). If you only deploy a ready-made tool as a sole proprietorship, you're mainly covered by the deployer's duties under Article 50(3)–(4) — chiefly making sure customers actually see that they're talking to a machine. When in doubt about your exact role — consult a lawyer.

How much time do I have to adapt the chatbot to transparency requirements?

Transparency requirements apply from 2 August 2026 — which means now. Check your chatbot's and phone AI's first phrase today, and if it doesn't clearly say it's a machine — fix it right away.

Do I need a dedicated person to handle chatbot escalations?

The regulations don't require this explicitly. But practically — there must be someone who handles cases the automation can't handle. In a small business, this is usually the owner or the person responsible for customer contact. Important that this person is available at specific hours and that the customer knows when they can expect a response.

Can I use AI to write social media posts?

Yes, you can. AI Act doesn't prohibit generating marketing content by AI. However, remember the general rules: don't mislead customers, don't impersonate someone else, apply RODO principles to personal data you process in content.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →