Your Chatbot Has a New Legal Obligation From August 2026

S

omewhere in your organisation, someone is using ChatGPT to draft a donor email, a board update, or a LinkedIn post. Right now, without a policy, a process, or anyone else knowing. That's not a hypothetical. That's Tuesday.

And from 2 August 2026, that ungoverned use stops being a communications asset and starts being a legal exposure.

The EU AI Act is not a new law you can file away as "for the tech team." If your organisation deploys any AI system that interacts with people in the EU — a chatbot, an AI-assisted intake form, an automated response tool — you now have a live legal obligation to tell them they're talking to a machine. That single requirement, buried in Article 50, will catch more purpose-driven organisations off guard than almost any other piece of EU legislation in the last decade.

Most organisations treat the EU AI Act as a compliance checkbox, owned by legal. It isn't.

The Act phases in over several years, and the headline-grabbing "high-risk system" obligations — the ones covering recruitment tools, credit scoring, and similar use cases — were pushed back to December 2027. That extension has created a dangerous misreading: the idea that nothing meaningful happens this August.

Three obligations are live from August 2026, and all three sit squarely in communications departments:

  • Chatbot and AI-assistant disclosure.
    If your organisation uses an AI chatbot, virtual assistant, or automated response system to interact with donors, members, stakeholders, or the public, those people must be told they're interacting with AI. This is a communications and UX obligation before it's a legal one.
  • General-purpose AI penalty enforcement.
    The rules for GPAI providers have applied since August 2025. From this August, the penalty framework behind them becomes fully active.
  • Prohibited-practice enforcement.
    The bans that took effect in February 2025 now come with full investigatory possibilities for national authorities.

The problem is not the law, but that most purpose-driven organisations have no system for knowing where AI is already being used across their communications — by staff, by volunteers, by whichever well-meaning team member found a useful tool last spring. You cannot govern what you cannot see. That's a dangerous structural problem.

So? How to best tackle the new laws? By implementing a lightweight AI governance layer built into your existing communications infrastructure. Just follow these four simple steps:

1. Map it.
Before you can disclose or govern anything, find out where AI already touches your external communications: chatbots, auto-reply tools, AI-drafted content, AI-assisted translation. Most organisations are surprised by how much surfaces here.

2. Disclose it.
Anywhere a chatbot or AI assistant interacts directly with an external audience, add clear, simple disclosure. This is a copywriting task as much as a legal one. It builds trust rather than undermining it.

3. Govern it.
Set a short, usable policy: what AI tools staff may use, for what purposes, and with what human review before anything goes external. This is where a prompt library and an approval workflow earn their keep.

4. Document it.
Keep a simple record of your AI use and your disclosure practices. If a regulator or a board member ever asks, you want an answer ready.

This is precisely the kind of structure that separates organisations with a communication system from organisations running on habits and hope.

We've seen this pattern before the Act even existed. Every client engagement that starts with an AI governance conversation surfaces the same thing: leadership assumes AI use is contained to one or two tools, and it never is. Sometimes, they even encourage it to cut costs, but are not interested in the details. Once you map it properly, you typically find AI touching four or five different points in the communications chain, often even including channels the comms lead didn't know existed.

Organisations that built a simple governance layer before regulatory pressure arrived aren't scrambling now. They're treating 2 August 2026 as a formality, not a deadline. That's the difference structure makes.

You don't need a big-bang compliance project. You need fifteen minutes to work out where you actually stand.

Book a CommsOps Blueprint discovery call, and we'll help you map exactly where AI is already touching your communications, and what a proportionate, governed response looks like for an organisation your size. No scare tactics. No legalese. Just structure.

Alive Communication builds the communication infrastructure purpose-driven organisations need to scale responsibly — including how they govern AI. Get in touch at alivecommunication.co.

Smiling woman with curly blonde hair, wearing glasses, a white top, and a necklace with a round pendant.

Connect with Kristin!

Follow me on LinkedIn for unfiltered thoughts on scaling mission-driven brands, AI governance, and the architecture of high-impact communication.

The CommsOps Blueprint
straight to your inbox!

@-Symbol icon in black.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Join founders and CCOs reading Structured Impact, our executive briefing.