Most customer-facing chatbots are not classified as high-risk under the EU AI Act, but the answer depends entirely on what the chatbot decides rather than the fact that it is a chatbot. Annex III lists the domains that trigger high-risk status, including employment decisions, credit and insurance eligibility, access to essential public services, law enforcement, and biometric categorization, so a support chatbot that only answers product questions typically falls outside that list. A chatbot that screens job applicants, recommends loan or insurance terms, or gates access to a benefit is very likely high-risk and subject to the fuller set of obligations, including risk management, human oversight, and conformity assessment, mostly applying from 2 August 2026. Even a low-risk chatbot still carries a transparency duty under Article 50 to disclose that users are interacting with AI unless that is already obvious from context. The safest approach is to map the chatbot's actual functions against Annex III rather than assume its risk tier from its interface. This is general guidance, not a formal legal classification, and should be confirmed for the specific deployment. Nanobase AI performs this classification exercise for clients and documents the reasoning behind each determination.
Classify the function, not the interface
The single most common mistake in EU AI Act classification is treating "chatbot" as a category the law recognizes. It does not. The Act classifies systems by what they decide or influence, and a chatbot is just a delivery mechanism, the same way a web form or a mobile app is. Two chatbots with identical architecture can land in completely different risk tiers depending on what happens behind the conversation. A classification exercise that starts with "what does this system decide" produces a defensible answer; one that starts with "it's a chatbot" usually does not.
Running the Annex III check
Annex III lists the specific domains that trigger high-risk status. Walking a chatbot's actual functions against this list, rather than its marketing description, is the only reliable classification method.
| Chatbot function | Annex III category | Likely classification |
|---|---|---|
| Answers product and billing questions | Not listed | Not high-risk, but Article 50 transparency still applies |
| Screens or ranks job applicants | Employment (Annex III.4) | High-risk |
| Recommends credit limits or loan terms | Credit scoring (Annex III.5) | High-risk |
| Triages insurance claims or pricing eligibility | Insurance risk assessment (Annex III.5) | High-risk |
| Gates access to a government benefit | Essential public services (Annex III.5) | High-risk |
| Performs biometric identification from voice or face | Biometric categorization (Annex III.1) | High-risk |
A chatbot performing more than one of these functions is classified by its highest-risk function, not averaged across all of them. Walking each function against Annex III individually, rather than judging the chatbot as a whole, is what produces a defensible classification.
The transparency duty that applies either way
Even a chatbot that clears the high-risk bar entirely still carries an obligation under Article 50: users must be told they are interacting with an AI system unless that is obvious from context. This applies regardless of risk tier and is frequently overlooked because teams focus their compliance attention entirely on the high-risk question. A disclosure banner or an opening line stating the assistant is AI-based satisfies this in most implementations. The Article 50 disclosure duty applies regardless of risk tier, so it should be treated as a default build requirement for every chatbot, not an afterthought for the high-risk ones.
What changes if the chatbot is high-risk
Landing in the high-risk category is not disqualifying, but it does add real engineering and documentation work before launch:
- A risk management system covering the system's full lifecycle, not just a one-time review.
- Technical documentation describing training data, intended purpose, and known limitations.
- Human oversight mechanisms, meaning a person can review, override, or stop the system's decisions.
- Logging sufficient to reconstruct how a given output was produced.
- A conformity assessment before the system goes into service, mostly required from 2 August 2026.
These duties apply at the point a chatbot's output materially affects a person's access to employment, credit, insurance, or public services, not just when the company intends that outcome.
This is general information, not a formal legal classification, and should be confirmed against the chatbot's specific deployment.
Frequently asked questions
Is a customer support chatbot ever high-risk?
Rarely, if it is limited to answering questions about products, orders, or account status. It becomes high-risk only if its output starts to gate something like a refund eligibility decision, a service downgrade tied to a scored assessment, or another Annex III function rather than pure information retrieval.
Does using a third-party chatbot platform change the classification?
No. The classification follows the system's function, not who built the underlying platform. A company deploying a vendor's chatbot for a high-risk use, such as loan pre-qualification, still carries deployer obligations even though it did not write the underlying model.
What if a chatbot's risk level is genuinely unclear?
Document the reasoning either way. Regulators and auditors generally accept a documented classification rationale, including one that concludes "not high-risk," far more readily than an undocumented assumption, and the exercise itself often reveals overlooked functions.
Does an insurance chatbot always count as high-risk?
Not automatically. A chatbot that only explains policy terms or FAQs is not the same as one that assesses risk or eligibility. See how this line is drawn in practice in our overview of AI in insurance underwriting and claims.
How Nanobase AI helps
Nanobase AI, an enterprise AI engineering company headquartered in Silicon Valley, performs Annex III classification exercises for client chatbots and conversational AI systems, mapping each function against the high-risk list and documenting the reasoning so it holds up under audit. For systems that land in the high-risk tier, we help build the technical documentation, logging, and human oversight controls the Act requires as part of our AI security and compliance services. Related classification questions are covered in our EU AI Act, GDPR, and KVKK compliance checklist.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.