Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Why AI compliance matters for chatbots
Build governance controls for customer-facing, employee-facing and public AI chatbots. The practical starting point is to list AI systems, identify who is affected, document data use, and decide which workflows need formal review before launch or scaling.
Common AI use cases to inventory
- customer-service chatbot
- sales or product recommendation chatbot
- employee helpdesk assistant
- health, finance or legal information chatbot
- AI agent that triggers actions
- public website chatbot
Higher-risk signals to watch
- users may not know they are talking to AI
- the chatbot handles sensitive data or vulnerable users
- the chatbot can take actions or influence eligibility
- there is no human escalation or output monitoring
These signals do not automatically decide the legal classification. They tell the team when to escalate, gather evidence and use a formal risk assessment.
Controls to put in place this month
- Clearly disclose AI interaction when required.
- Limit sensitive data and high-impact advice.
- Add human escalation for important decisions or vulnerable users.
- Monitor harmful, misleading or discriminatory outputs.
- Keep prompts, knowledge sources, vendor settings and review dates documented.
Suggested review path
For this industry, start with the use-case checker, then use the risk matrix to prioritise systems, and finally document the controls in your AI inventory.
Worked example: public website chatbot
A public chatbot should be clearly identified when users might believe they are speaking with a human. Risk rises if it gives advice, makes promises, processes sensitive data or affects access to services.
Evidence to keep
- Bot purpose, allowed topics and prohibited topics.
- AI disclosure wording and handoff-to-human rules.
- Data retention and prompt/logging controls.
- Testing records for hallucinations, harmful advice and misleading outputs.
30-day improvement plan
- Add clear AI labels and human contact paths.
- Block sensitive-data collection unless reviewed.
- Create escalation rules for complaints, legal, medical, financial and safety questions.
- Review transcripts for unsafe or misleading responses.
FAQ
Is AI in chatbots always high-risk?
No. Risk depends on the specific use case, affected people, data, role and deployment context.
What should I document first?
Start with an AI inventory entry, owner, intended use, data categories, affected users, vendor/model documentation and review date.
Can this replace legal advice?
No. It is a practical readiness guide, not legal advice.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.