Skip to content
Chatbotscape
Editorial flat-vector illustration for Customer Service Automation in 2026: What to Automate, and the EU Rule That Started Applying on 2 August
29 min read

Customer Service Automation in 2026

What to Automate, and the EU Rule That Started Applying on 2 August

Quick answer: Customer service automation is the practice of handling support requests without a person in the loop, whether through a chatbot, a help center, macros, routing rules or a workflow that never touches an agent. Two things decide whether it works. The first is selection: automate the requests where automation genuinely reduces the customer's work, not the ones where it merely reduces yours. The second is new and easy to file under the wrong heading. The AI Omnibus, in force since 27 July 2026, moved the high-risk obligations out to 2 December 2027 and 2 August 2028. If you read that as a blanket postponement of the AI Act, the part that most concerns a support bot went the other way. The obligation to tell a person they are interacting with an AI system was not moved. It began to apply on 2 August 2026, it reaches providers established outside the EU when the output of their AI system is used in the EU, and it is the provision aimed squarely at the interaction your support bot is having.

What actually changed on 2 August, and what did not

The EU AI Act has always had a staggered timetable. We had expected the dates that mattered for 2026 to arrive together on 2 August, and then one of them moved.

The AI Omnibus entered into force on 27 July 2026, six days before that deadline, having been proposed as part of the digital omnibus package on 19 November 2025. The Commission's own summary organizes the change under five headings, and it is worth taking them as the Commission groups them rather than compressing them into "the AI Act was relaxed."

Under Extended timelines it lists exactly two items: high-risk AI systems in Annex III now apply from 2 December 2027, and high-risk AI embedded in physical products under Annex I from 2 August 2028. Under Innovation support it extends some measures previously reserved for SMEs to small mid-cap companies, and widens access to regulatory sandboxes while adding an EU-level one. Under Reduced administrative burdens it extends simplified obligations to small mid-cap companies, simplifies the AI literacy requirement, and simplifies registration of exempted systems in the EU database. Under Safety and fundamental rights it adds a prohibition on AI systems generating non-consensual sexually explicit and intimate content or child sexual abuse material, and permits processing special categories of personal data in order to detect and correct bias. Under AI governance alignment it carries two items: it extends the AI Office's oversight to certain systems, including those built on general-purpose models and those embedded in large online platforms and search engines, and it clarifies the interplay between the AI Act and other EU laws while simplifying procedures for conformity assessment bodies.

That last heading is worth pausing on, because it runs against the simplification story: one of the Omnibus's changes is more oversight, not less.

Read the list again for what is absent. Article 50, the transparency chapter, is not in it.

The Commission's FAQ is explicit on the point: "Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision." There is one narrow grace period, and it is not the one people assume. It covers only the machine-readable marking and detection obligation for AI-generated content under Article 50(2), only for systems already placed on the market before 2 August 2026, and it runs to 2 December 2026. Content generated before 2 August 2026 does not have to be labelled retroactively, though the Commission adds that it encourages relevant deployers to do so where possible.

So the summer's story, compressed: the part of the AI Act that most small businesses running a support bot are outside moved to 2 December 2027 and 2 August 2028, and the part that such a business is quite plausibly in arrived on schedule. We are not publishing a delta in months, because neither Commission page states the original application dates the Omnibus moved from, and we have not read the legislative text to establish them.

The obligation, in the Commission's own words

Article 50(1) requires providers of AI systems that interact directly with people to design and develop those systems so that the individuals concerned are informed that they are interacting with an AI system, unless this is obvious.

The Commission's guidelines set out four cumulative criteria for when that applies. All four must hold. We reproduce the Commission's wording and order below, with the repeated "must" dropped because the introductory sentence already carries it, and the verbs inflected to suit:

  1. The system qualifies as an AI system.
  2. It is designed for a genuine two-way exchange with people, rather than merely collecting data or providing automated responses.
  3. The interaction is direct, meaning the AI itself communicates with the person rather than through a human intermediary.
  4. The interaction is with natural persons, whether consumers, professionals or other users.

Systems operating solely in the background, machine-to-machine, or without direct contact with people fall outside it. A support chatbot on your website or in a messaging channel meets all four without much argument. A routing rule that silently assigns tickets does not meet the second.

On timing and manner, the Commission says people must be notified "from the start of the first interaction in a clear and distinguishable manner and in accordance with accessibility requirements."

Two details are worth more attention than they usually get. The first is the "obvious" exception, which is where a lot of wishful thinking goes to live. The Commission's test is an average person who is "reasonably well-informed, circumspect, and observant," and it adds that the exception "should be interpreted in a restrictive manner, given that it deprives people of transparency." A widget labeled with your company name and a friendly first name is not, on that test, obviously an AI.

The second is the penalty and who applies it. The Commission states that fines "can reach up to 15 million euros or 3% of total worldwide turnover for the preceding financial year," and that proportionality can be taken into account for SMEs and small mid-cap companies. Enforcement sits mainly with national competent market surveillance authorities. The AI Office has what the Commission calls a limited role, confined to systems built on general-purpose models where the same entity supplies both, and to systems integrated into very large online platforms and search engines designated under the Digital Services Act; the European Data Protection Supervisor enforces against the EU's own institutions. The practical consequence is that "how strictly will this be applied to a company my size" is mostly a question about your member state rather than about Brussels.

Whose duty is it when you rent the bot?

Here is the part that matters most to this site's readers, and it is our reading rather than the Commission's statement.

Article 50(1) is written on providers. The Commission's phrasing is that "Providers of AI systems that directly interact with people must design and develop those systems in such a way that the individuals concerned are informed that they are interacting with an AI system, unless this is obvious." If you bought your chatbot from a vendor, the design duty in that sentence describes the vendor, not you. Providers established outside the EU are caught too, the Commission says, "if the output of their AI system is used in the EU."

A note on the source, because it matters to anyone checking our reading against it. The same FAQ carries a second, near-identical sentence naming chatbots, AI agents and avatars explicitly, and files that one under Article 50(2) rather than 50(1). We have quoted the sentence the Commission files under 50(1) and are flagging the other rather than tidying it away.

Two adjacent provisions are out of this guide's scope and should not be assumed away. Article 50(2) covers the marking of AI-generated content, including text, in a machine-readable format. Whether a generative support bot's answers fall inside that is a provider-side question with real carve-outs attached, and we do not answer it here. Article 50(5), which the Commission lists alongside 50(1) and 50(2) among the provider duties, is likewise not covered. Both belong on the list of things to raise with your vendor.

You are a deployer: a person or body using an AI system under your authority in a professional capacity. The Commission is clear that your employees are not separate deployers, and that you remain the deployer even where contractors or freelancers operate the system on your behalf and under your control. The deployer duties Article 50 spells out are the emotion-recognition and biometric-categorisation notice under 50(3), and under 50(4) the labelling of deepfakes and of AI-generated text published to inform the public on matters of public interest without human review or editorial control. On our reading neither describes an ordinary support bot answering questions about delivery times.

It would be comfortable to stop there and conclude that disclosure is the vendor's problem. We do not think that conclusion is safe, for a reason that is operational rather than legal: you control the configuration that can defeat the vendor's disclosure. You name the bot. You write the greeting. You choose the avatar. A platform can ship a compliant "You are chatting with an automated assistant" line and a deployer can rename the bot Sarah, give it a photograph and open with "Hi, I'm Sarah from support." Whether that shifts any part of the provider's role onto the deployer is a genuine legal question, it depends on facts and on provisions this guide does not cover, and it is exactly the sort of question to put to a lawyer rather than to a review site.

What we can offer is the practical reframing. For a business that rents its chatbot, this is a procurement question before it is a compliance question, and it resolves into four things to ask any vendor, in writing, before you sign:

  • Where in the product is the AI disclosure made, and at what point in the conversation does it appear?
  • Can it be disabled or edited by an administrator, and does the product warn me if I do?
  • What happens to it when I rename the bot, change the avatar or write a custom greeting?
  • Which of us does your documentation treat as the provider for Article 50 purposes?

An answer to the fourth question is informative whatever it says. A vendor that has not thought about it has told you something.

We should say what we have and have not asked

Applying that standard to our own work: across our fifteen published platform reviews, the string "GDPR" appears in eleven and "AI Act" in two. We have asked vendors about data protection as a matter of routine and about this regime almost never, which is a gap in our coverage rather than a judgment about the platforms.

Our chatbot best practices guide already tells operators not to let a bot pretend to be human, and names the EU AI Act among the reasons, in three separate places. That instruction is right and predates this page. What it does not do is say which provision, on whom it falls, or from what date, because when it was written none of those had bitten yet. We are adding the specifics here rather than quietly rewriting that page, and the vendor questions above are going into our review protocol.

Now the harder question: what should you automate?

Compliance tells you how to disclose. It does not tell you what to hand to a machine, and that decision is where most of the value and most of the damage sits.

The default selection test, in our reading of how these projects get scoped, is volume: automate whatever arrives most often. The metric that follows is deflection, which counts conversations that did not reach a human. We have written at length about why that metric flatters itself, and the short version is that a customer who gave up and a customer who was helped both register as deflected.

We want to propose a different selection test, and it is the reason this guide's companion entry today is customer effort score. Automate a request type when automation reduces the customer's work, not when it reduces yours. Those two often coincide, which is why automation works at all. When they diverge, deflection cannot see it and effort can.

The table below is our editorial judgment for a typical small business rather than a measurement, and it is meant as a starting sort rather than an answer.

Request typeEffort with a good botEffort with a queueAutomate?
Order or delivery statusSeconds, no waitingMinutes plus hold timeYes, first
Opening hours, location, policy lookupsInstantDisproportionateYes
Password resets and account self-serviceInstant, any hourHigh, and often out of hoursYes
Appointment booking and reschedulingLow if the calendar is liveModerateYes, if integrated
Returns within a clear policyLowModerateYes, with an exception path
Product fit and comparison questionsDepends entirely on data qualityLow with a knowledgeable agentOnly with live data
Billing disputesHigh, the bot cannot decideLow, a person can decideNo
Complaints and service failuresHigh, and it compounds the failureLowNo
Anything involving a vulnerable customerHighLowNo

Three observations fall out of it. First, the top three rows share a property: the customer knows exactly what they want, and what they want is either a lookup or a self-contained action the system can complete on its own. That is the shape of the cleanest automation candidate, and it is a better predictor than volume. Rows four and five qualify on a condition rather than outright, because booking and returns are transactions whose outcome depends on state the bot does not hold: they automate well once the calendar or the returns system is genuinely wired in, and badly when the bot is only collecting details for someone to process later. Row six is the hinge. Product fit questions can be the best or the worst thing on this list, and which one they are is decided entirely by whether the bot reads live catalog data, which is the subject of our ecommerce playbook.

Second, the bottom three rows share a different property. In the first two the customer needs a decision, not an answer, and a bot that cannot make the decision can only take a message; taking a message while appearing to help is the highest-effort outcome available. The last row is there for a different reason and the generalization does not cover it: a customer in a vulnerable situation may want something perfectly simple and should still reach a person. Our guide on when not to use a chatbot is the longer treatment of that boundary. That page also flags disclosure as a category of regulatory risk; this one supplies the provision, the duty-holder and the date.

The corollary is unpopular with anyone selling automation by seat count: the escape hatch is part of the automation, not an admission that it failed. A handoff that fires quickly is what keeps the bottom rows out of the bot, and our escalation playbook covers the triggers. A late handoff, where the bot loops twice before giving up, costs bot effort and human effort and customer effort at once.

Build order

Nine steps, in the order we would run them. The order matters at least as much as the contents. The failure we would most expect is doing step four before step two, which is buying and building the automation before checking that the data it needs is actually reachable.

  1. Pull ninety days of tickets and sort by request type, not by channel. You are looking for the lookup-shaped and self-service-shaped ones.
  2. Check whether the data behind each candidate is actually reachable. An order-status bot without an order system is a form.
  3. Write the disclosure line and the escape phrase before you write any flow. They are the two sentences you will never regret.
  4. Automate one request type end to end. Not five at thirty percent.
  5. Wire the handoff and staff it during the hours the bot is live.
  6. Instrument it: containment, abandonment, handoff rate and time-to-handoff, plus a post-chat effort question with the response rate published beside it. Our metrics guide covers the set.
  7. Run the failure cases deliberately before launch, using our QA testing protocol.
  8. Decide the decline policy: what the bot says when it does not know, per our confidence policy guide.
  9. Add the second request type only after the first one holds for a month.

Where it breaks

Automating the complaint queue because it is expensive. It is expensive because it needs judgment. Automation moves the cost onto the customer and then onto your reputation.

Treating disclosure as a banner. The Commission's language is about the start of the first interaction, clear and distinguishable, and accessible. A line in a privacy policy is none of those things.

Buying an AI layer before fixing the knowledge behind it. A confident wrong answer is worse than a slow right one, and our guide on reducing hallucinations is about the difference between the model and the material.

Measuring the program on deflection alone. You will optimize toward customers giving up quietly. Read containment and effort together, or you are grading your own homework.

Assuming the regime does not reach you because you are not in Europe. The Commission states that providers outside the EU are subject to the Act if the output of their system is used in the EU. Whether and how that lands on a deployer in your position is a question for counsel, but "we are not an EU company" is not by itself the end of the analysis.

Hiding the human option to protect the automation rate. It converts a two-minute contact into a bad afternoon and a review. In our judgment it is among the most damaging things a team can do to its own numbers, because it improves every dashboard metric while degrading the thing the metrics exist to describe.

FAQ

What is customer service automation?

It is handling customer requests without a person in the loop, through chatbots, self-service help centers, automated routing, macros or workflows that resolve a ticket end to end. The chatbot is the visible part; most of the value in a small operation usually comes from the unglamorous parts, such as answering status questions from live order data and letting customers reset their own credentials.

What should I automate first?

Requests where the customer already knows what they want, and what they want is either a lookup or a self-contained action the system can complete on its own: order and delivery status, opening hours and policies, password resets and account self-service. They are high volume, low judgment, and automating them reduces the customer's work rather than just yours. Leave billing disputes, complaints and anything involving a vulnerable customer with a person.

Does the EU AI Act mean I have to tell customers they are talking to a bot?

Article 50 of the AI Act applies from 2 August 2026, and it requires that people interacting directly with an AI system are informed of that fact unless it is obvious, from the start of the first interaction. The obligation as the Commission describes it is written on providers of the system, which for most small businesses means the platform vendor rather than the business renting it. That said, the business controls the naming, avatar and greeting that can undercut the disclosure. This is not legal advice and your situation may differ; the practical step is to ask your vendor in writing where the disclosure appears and whether you can change it.

Wasn't the EU AI Act delayed?

Part of it was. The AI Omnibus entered into force on 27 July 2026 and moved the high-risk obligations for Annex III systems to 2 December 2027, and for high-risk AI embedded in physical products to 2 August 2028. The Commission's own summary of the extended timelines lists only those two. The Article 50 transparency obligations were not among them and applied on 2 August 2026. There is one narrow grace period, running to 2 December 2026, and it covers only the machine-readable marking and detection obligation for AI-generated content under Article 50(2), and only for systems placed on the market before 2 August 2026.

What are the penalties?

The Commission states that fines can reach up to 15 million euros or 3 percent of total worldwide turnover for the preceding financial year, and that proportionality can be taken into account for SMEs and small mid-cap companies. Enforcement sits mainly with national market surveillance authorities, with the AI Office holding what the Commission calls a limited role, so practice will vary by member state.

How much of my support volume can realistically be automated?

We publish no figure, because the honest answer depends on your ticket mix rather than on your platform, and a percentage quoted without a ticket mix is marketing. Sort ninety days of tickets by request type and count how many are lookups or self-contained actions against data you can actually reach. That count is your ceiling, and you should expect to reach part of it rather than all of it.

Should I measure automation with deflection rate?

Not on its own. Deflection counts conversations that did not reach a human, and a customer who gave up in frustration counts the same as one who was helped. Read it next to containment, abandonment and a post-effort question, and publish the survey response rate beside any score, because the people who abandoned are both the highest-effort cases and the least likely to answer a survey.

Which platform is best for customer service automation?

We publish no ranking in this guide. Our best chatbot for customer support list is where our comparative assessment lives. The questions we would carry into it are how the platform sources live data for status-type requests, how fast and how configurable the human handoff is, and where its AI disclosure appears.

Does automation reduce customer satisfaction?

It depends on what you automated. Automating a lookup usually raises satisfaction, because waiting for a person to read a tracking number back to you is not a service experience anybody values. Automating a decision usually lowers it, because the customer has to get past the bot before the real process starts. The metric that separates the two cases better than satisfaction does is customer effort.

Sources

  • European Commission, Directorate-General for Communications Networks, Content and Technology. Transparency obligations under Article 50 of the AI Act, FAQ page, page's own last-update stamp 24 July 2026, read 18 August 2026 — the source of every Article 50 statement on this page. Specifically: that Article 50 "applies as from 2 August 2026" and that "from that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision"; that the grace period is "envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content (Article 50(2))," with compliance for those due from 2 December 2026, and that content generated before 2 August 2026 need not be labelled retroactively; the definition of a provider and the statement that providers outside the EU are subject to the Act "if the output of their AI system is used in the EU"; the phrasing quoted on this page for the Article 50(1) duty, "Providers of AI systems that directly interact with people must design and develop those systems in such a way that the individuals concerned are informed that they are interacting with an AI system, unless this is obvious"; the FAQ's separate and near-identical sentence naming "chatbots, AI agents, and avatars," which that document files under Article 50(2) rather than 50(1) and which this page flags rather than silently reconciles; the listing of Articles 50(1), (2) and (5) as the provider transparency obligations, and the description of Article 50(2) as covering synthetic "audio, image, video or text content"; the definition of a deployer, the exclusion of personal non-professional use, the statement that individual employees are not separate deployers and that a legal person "remains a deployer even if third parties (e.g. contractors, freelancers) are involved"; the four cumulative criteria for the Article 50(1) obligation, quoted in the order and wording the page gives them; the statement that people must be notified "from the start of the first interaction in a clear and distinguishable manner and in accordance with accessibility requirements"; the "obvious" exception, its average-person test using the words "reasonably well-informed, circumspect, and observant," and the instruction that it "should be interpreted in a restrictive manner, given that it deprives people of transparency"; the deployer obligations under Articles 50(3) and 50(4); the statement that content generated before 2 August 2026 need not be labelled retroactively and that the Commission nonetheless "encourages relevant deployers to do so, where possible"; and the enforcement and penalty paragraph, including fines that "can reach up to 15 million euros or 3% of total worldwide turnover for the preceding financial year," the proportionality allowance for SMEs and small mid-cap companies, enforcement resting "mainly" with national competent market surveillance authorities, the AI Office's "limited role" confined to systems built on general-purpose models where one entity supplies both and to systems integrated into DSA-designated very large online platforms and search engines, and the European Data Protection Supervisor's role for EU institutions, bodies and agencies. digital-strategy.ec.europa.eu
  • European Commission. AI Omnibus enters into force, news article, publication date 27 July 2026, page's own last-update stamp 31 July 2026, read 18 August 2026 — the source for the Omnibus entering into force on 27 July 2026, for its origin in the digital omnibus package proposed on 19 November 2025, and for the contents of its "Extended timelines" section: high-risk AI systems in Annex III applying from 2 December 2027 and high-risk AI embedded in physical products under Annex I from 2 August 2028. Also the source for the five-heading structure reproduced on this page and for the items filed under each: Innovation support (extension of some SME measures to small mid-cap companies; expanded regulatory sandboxes including an EU-level sandbox), Reduced administrative burdens (simplified obligations extended to small mid-cap companies; simplified AI literacy requirement; simplified EU database registration for exempted systems), Safety and fundamental rights (the prohibition on AI generating non-consensual sexually explicit and intimate content or child sexual abuse material; the allowance to process special categories of personal data to detect and correct bias), and AI governance alignment (the AI Office's extended oversight of certain systems, including those built on general-purpose models and those embedded in large online platforms and search engines; and the clarification of the interplay between the AI Act and other EU laws together with simplified procedures for conformity assessment bodies). The page links the full legislative text at the Official Journal reference OJ:L_202601744. The observation that Article 50 does not appear in that "Extended timelines" list is ours, and is a reading of the Commission's own summary rather than a statement the Commission makes. digital-strategy.ec.europa.eu
  • Chatbotscape. Chatbot best practices — re-read on 18 August 2026 to confirm the characterization above. That page instructs operators not to let a bot pretend to be human and names the EU AI Act among the reasons in three places, without specifying the provision, the duty-holder or the application date. This page supplies those and does not contradict it. That page also cites FTC guidance; we have not verified any FTC material for this guide and make no claim about US requirements here.
  • Site-wide string counts across the fifteen published platform reviews, run 18 August 2026 after this page's final edit: case-insensitive matches for "GDPR" in 11 and "AI Act" in 2. Published as a transparency statement about the questions our review protocol has and has not put to vendors, not as a claim about the platforms themselves.
  • Ahrefs Keywords Explorer, US overview and volume-by-country, queried 18 August 2026 — the search-demand, difficulty, parent-topic and country-split figures in this page's keyword note, including the check that revealed the calendar slug's collision with a published glossary entry's declared secondary keywords, and the checks that routed 'help desk automation' to the best-list stream.
  • Chatbotscape platform reviews — the four platforms in this page's related reviews are ones we have evaluated hands-on. We have run no comparative test of AI-disclosure implementation, handoff latency or automation reporting across them, and this guide therefore contains no ranking.
  • Chatbotscape evaluation methodology. /methodology (continuously updated).

About this guide

Chatbotscape launched in 2026 as an independent review site for chatbot platforms. This guide is part of our SMB chatbot Academy. It covers two decisions that sit underneath any customer service automation project: which request types are worth handing to a machine, judged by whether automation reduces the customer's work rather than only yours, and what the EU transparency obligation that began applying on 2 August 2026 asks of a business that rents its chatbot from a vendor. The measurement half is in our chatbot metrics guide and the boundary cases are in our guide on when not to use a chatbot.

Methodology

Every regulatory statement on this page was read on 18 August 2026 from two European Commission pages and quoted from their own text rather than paraphrased from legal commentary or news coverage. Both pages carry their own update stamps, which are recorded in Sources. Where the Commission's wording is distinctive, particularly the average-person test for the "obvious" exception and the penalty figures, it is reproduced rather than restated. The four cumulative criteria are reproduced in the Commission's order and wording, with the repeated "must" dropped and the verbs inflected accordingly as the only alteration. One timing point is worth stating: the FAQ carries an update stamp of 24 July 2026, three days before the AI Omnibus entered into force, so its description of the AI Office's role as limited predates the Omnibus item that extends that Office's oversight. We report both as their respective pages state them and do not attempt to reconcile them. We did not read the legislative text itself, we consulted no legal adviser, and we have not examined any national implementation. This site writes in US English; where this page quotes or closely paraphrases the Commission, British spellings such as "labelled" and "categorisation" are retained deliberately rather than normalized, so that a reader searching the source text finds the same words. Articles 50(2) and 50(5) are outside this guide's scope and are flagged as open rather than resolved.

The editorial judgment on this page is listed here rather than flagged line by line, and the list is intended to be exhaustive. It comprises, in the order the page raises them:

  1. The framing that a reader may have filed the Omnibus as a blanket postponement, and the assessment that the Article 50 duty is "the provision aimed squarely at the interaction your support bot is having." We make no claim about how any particular publication reported the Omnibus, and cite none.
  2. The observation that Article 50 is absent from the Commission's own "Extended timelines" summary, and the remark that the AI governance alignment heading runs against a pure simplification reading.
  3. The statement that most small businesses running a support bot are outside the high-risk regime. This is our reading of the Annex III scope rather than a Commission finding, and it is contestable, since Annex III reaches employment and creditworthiness use cases that small businesses do sometimes automate.
  4. The application of the four cumulative criteria to two fact patterns: that a website or messaging-channel support chatbot meets all four, and that a silent ticket-routing rule fails the second.
  5. The conclusion that a widget carrying only a company name and a friendly first name is not obviously an AI on the Commission's average-person test. The Commission supplies the test; it does not supply this outcome.
  6. The reading that if you bought your chatbot from a vendor, the Article 50(1) design duty describes the vendor rather than you, and the related assessment that the Article 50(3) and 50(4) deployer duties do not describe an ordinary support bot answering delivery questions.
  7. The argument that the practical question for a renting operator is a procurement question rather than a compliance question, and the four vendor questions that follow from it.
  8. The claim that configuration choices such as naming, avatar and greeting can undercut a provider's disclosure, together with our explicit refusal to say what legal consequence that has.
  9. The judgment that a disclosure buried in a privacy policy does not meet the Commission's clear, distinguishable and accessible standard, and the assessment that "we are not an EU company" does not by itself end the analysis.
  10. The characterization of volume as the industry's default automation-selection test, and the alternative test that automation should be judged on whether it reduces the customer's work.
  11. The nine-row request-type table and its effort estimates, which are planning judgments for a typical small business and not measurements; the lookup-versus-transaction-versus-decision distinction the table rests on; and the separate reason given for its last row.
  12. The nine-step build order and the failure mode named against it.
  13. The assessment that hiding the human option is among the most damaging things a team can do to its own numbers.
  14. Four judgments carried in the FAQ and the enforcement section: that the strictness question is mostly a question about your member state rather than about Brussels, which is a consequence we draw from the Commission's enforcement split rather than one it states; that automating a lookup usually raises satisfaction and automating a decision usually lowers it, neither of which we have measured; and that customers who abandon a bot session are both the highest-effort cases and the least likely to answer a survey, which is reasoning set out in full and labeled as such in our customer effort score entry.

None of these is a claim made by the European Commission.

We have run no comparative test of AI-disclosure implementation across chatbot platforms, we publish no automation-rate or deflection benchmarks in this guide, and the string counts reported about our own reviews were re-run after this page's final edit. See our methodology for how platform facts are verified.

Last updated

19 August 2026.