Skip to main content
Compliance

Digital Omnibus and the AI Act: what changes (and what was NOT postponed) if you use a chatbot

Francesco Sganga ·

Updated on:

On 27 July 2026 the “Digital Omnibus”, the AI Act simplification package, entered into force. The headline everyone reports is the postponement of the obligations for high-risk systems, pushed back to 2 December 2027 and 2 August 2028. But for most companies that use an AI chatbot the important point is a different one: the transparency obligation of Article 50 was NOT postponed and has been fully in force since 2 August 2026. In practice, the deadline that actually concerns anyone with a virtual assistant on their website, on WhatsApp or on the phone has already arrived. Let us look at what changed and what you need to do, without alarmism and without needless jargon.

Note: this article is for information purposes only and does not constitute legal advice. For your company’s specific obligations, consult a trusted professional.

What the Digital Omnibus is, in two lines

The Digital Omnibus is a European Commission package that simplifies and reschedules some parts of the AI Act (Regulation EU 2024/1689 on artificial intelligence). The stated goal is to ease the burden on businesses, especially SMEs and small mid-cap companies, and to allow more time where the technical rules were not yet ready.

The main simplifications concern: an extension of the high-risk deadlines, a broadening of the regulatory sandboxes, easier registration in the EU database, and lighter AI literacy obligations. The package also introduces a new explicit prohibition in Article 5: the AI generation of non-consensual intimate imagery and of child sexual abuse material.

What was postponed and what was not

This is the table that really matters. Many companies read “AI Act postponed” and breathed a sigh of relief. Careful: the postponement concerns high risk, not chatbot transparency.

Obligation Who it concerns New deadline
High-risk systems (Annex III, stand-alone) E.g. AI for recruitment, credit, essential services Postponed to 2 December 2027
High risk embedded in physical products (Annex I) Machinery, toys, lifts, devices Postponed to 2 August 2028
Transparency (Art. 50): chatbots and AI assistants Anyone using a conversational assistant In force since 2 August 2026 (not postponed)
Machine-readable marking of AI-generated content (Art. 50 §2) Anyone generating synthetic text, images, audio 2 December 2026 (only for systems already on the market)

The message is simple: if your virtual assistant is there to answer customers, inform them, provide support or collect requests, it falls under limited risk, and the only obligation that concerns it, transparency, is already fully applicable.

Why your chatbot is “limited risk” (and what that means)

The AI Act classifies systems by level of risk: the more a system can affect people’s rights, the more obligations it has. A virtual assistant for customer care, FAQs or lead qualification almost always falls under limited risk.

For this category there is one central obligation: transparency. Article 50 requires that whoever designs or uses an AI system intended to interact directly with natural persons does so in such a way that the user knows, from the very first interaction, that they are dealing with an artificial intelligence and not a person. No heavy technical documentation, no complex conformity assessment: you need to inform clearly.

One caveat: a chatbot can “slip” into high risk if it is used in sensitive contexts (for example decisions on hiring, access to credit or healthcare services). In those cases the rules are stricter and the deadlines postponed to 2027 and 2028 become relevant again. For standard customer support, however, the issue remains transparency.

What your company must concretely do from 2 August 2026

Translated into practice, here are the steps to comply with the transparency obligation:

  1. Declare the AI nature of the interaction. The user must know, before starting, that they are talking to a virtual assistant based on artificial intelligence.
  2. Explain what the assistant is for. One line about its purpose (informational support, FAQs, automated replies) is plenty.
  3. Add a disclaimer about the answers. Warn that answers are generated automatically and may not always be complete or correct.
  4. Invite users not to share personal or sensitive data in the conversation.
  5. Add a visible link to the Privacy Policy, accessible before the chat begins.
  6. Update your privacy notice to include processing via the AI assistant, the purposes and the legal basis.
  7. Ensure human intervention where needed, with escalation to an operator.

Much of this depends on the tool you use: a platform designed for the European market makes compliance far simpler, because it gives you the mechanisms ready-made instead of leaving you to build everything from scratch. If you want the bigger picture on the relationship between AI and personal data, you will find it all in our guide on AI and GDPR for companies.

Transparency changes for each channel

The obligation is the same, but the way to meet it changes depending on where your assistant speaks. Here is how it translates across the most common channels.

  • Website widget. Show an initial notice before the chat starts, covering the AI nature, purpose, disclaimer, an invitation not to enter data and a link to the privacy policy. The user must be able to close the widget without starting the conversation, with no pre-selected buttons or opt-out logic.
  • WhatsApp. Here the main mechanism is the disclaimer in the first message: the assistant introduces itself as virtual, explains what it can do and points to the privacy policy, also respecting Meta’s policies.
  • Email. When the assistant replies automatically to incoming email, the reply must state that it is generated by an artificial intelligence system. Users often do not expect it: the disclaimer is essential.
  • Voice (AI phone line). Transparency applies on the phone too: the caller must understand they are speaking with an automated assistant.

One last point: if the chatbot offers to continue on an external channel (for example WhatsApp), the user must be informed, before the redirect, that they will move to a third-party provider’s platform, with its own terms and privacy notice.

How Humassistant helps you stay compliant

Humassistant is designed for the European market and gives you the concrete tools to meet the transparency obligation of Art. 50, without having to reinvent anything. Responsibility for the configuration remains yours (you are the data controller), but the platform puts the essentials in your hands:

  • Guidelines for each channel. Inside the platform, for Widget, WhatsApp and Email, you find guidance on what the user must see, with ready-to-adapt sample texts.
  • Configurable disclaimers and notices. You can set the initial transparency message and the answer disclaimer for each channel.
  • Privacy policy templates. Ready-written sections (types of data, purposes and legal basis, data processor, AI transparency, retention) to integrate into your notice.
  • Escalation to a human operator when the conversation calls for it.
  • Data in the EU. Conversations are processed on Google Cloud infrastructure with a data center in Italy, in Milan.
  • No lock-in. Your data is exportable at any time.

For the formal details you can consult the legal area and the privacy policy. If you want to see how it fits into a broader customer support project, take a look at our customer care software and the virtual assistant for companies.

Frequently asked questions about the Digital Omnibus and the AI Act

Did the Digital Omnibus postpone the AI Act?

Only in part. It postponed the obligations for high-risk systems (to 2 December 2027 for Annex III and to 2 August 2028 for high risk in physical products). The transparency obligations of Article 50, which concern chatbots, were not postponed and apply from 2 August 2026.

From when is it mandatory to declare that a chatbot is an AI?

From 2 August 2026. Article 50 of the AI Act requires that the user be informed, from the very first interaction, that they are dealing with an artificial intelligence system. This deadline was not touched by the Digital Omnibus.

Does a chatbot have to declare it is not human?

Yes. For limited-risk systems, such as conversational assistants, the AI Act imposes a transparency obligation: the user must clearly know they are interacting with an artificial intelligence.

What does a company risk if it ignores the transparency obligation?

Breaching the transparency obligations of Art. 50 can lead to fines of up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher. Beyond the fine, a lack of transparency undermines user trust.

Is my customer assistant “high risk” or “limited risk”?

An assistant for FAQs, informational support or lead qualification is almost always limited risk, with the sole transparency obligation. It becomes potentially high risk if used for sensitive decisions, for example in employment, credit or healthcare.

What does the Digital Omnibus change for SMEs?

The package introduces simplifications aimed also at SMEs and small mid-cap companies, such as easier registration in the EU database and lighter AI literacy obligations. However, the transparency obligation for anyone using a chatbot remains firmly in place.


Want an AI for your customers that is built ready for the European rules? Discover Humassistant is GDPR-native, data in Milan, guidelines and disclaimers for every channel. Or talk to us.


Francesco Sganga

Scritto da

Francesco Sganga

Francesco Sganga is one of the founders of Humassistant, the Italian platform that centralizes email, WhatsApp, phone, chat and social into a single inbox. He writes about artificial intelligence applied to business communication, customer care and automation, always focused on the real needs of Italian SMEs.

Create your account for free.

Centralize your company communications in 5 minutes. No credit card required.

Start free

Prefer to talk it through first? Book 15 minutes with us →