Mercury Logo - Full version with bubbles and lettering "Mercury.ai" Conversational AI Platform

Solutions

Platform

Resources

Company

GDPR- & EU AI Act-compliant AI chatbot: What companies must pay attention to in 2026

Post

Compliance & Data Protection

GDPR- & EU AI Act-compliant AI chatbot: What companies must pay attention to in 2026

GDPR- & EU AI Act-compliant AI chatbot: What companies must pay attention to in 2026

Expert delivers presentation on AI architecture and Retrieval-Augmented Generation at a specialist conference

Author

Dr. Maximilian Panzner

Dr. Maximilian Panzner

Chief Technology Officer @Mercury.ai

Expert delivers presentation on AI architecture and Retrieval-Augmented Generation at a specialist conference

Author

Dr. Maximilian Panzner

Dr. Maximilian Panzner

Chief Technology Officer @Mercury.ai

Cover image for the post 'GDPR- & EU AI Act-compliant AI Chatbot: What companies must pay attention to in 2026'
Cover image for the post 'GDPR- & EU AI Act-compliant AI Chatbot: What companies must pay attention to in 2026'

10 Min. read time

In this article

A GDPR- and EU-AI-Act-compliant AI chatbot processes personal data on a valid legal basis and exclusively within the EU, transparently informs users that they are talking to an AI, and only provides traceable, source-based answers. In 2026, both regulatory frameworks apply in parallel: the GDPR regulates the handling of personal data, while the EU AI Act (Regulation (EU) 2024/1689) regulates the use of the AI system itself. Anyone deploying a chatbot in customer service, HR, or sales must comply with both simultaneously.

This guide explains what this means in practice and provides a checklist to evaluate any provider against.

At a Glance

  • Two regulatory frameworks, in parallel: GDPR (data protection) and the EU AI Act (AI system) apply simultaneously. One does not replace the other.

  • Most service chatbots are not high-risk systems under the EU AI Act. However, the operator remains responsible for classifying the specific use case.

  • Transparency obligation (Art. 50 EU AI Act): Users must be able to recognize that they are interacting with an AI.

  • Data location is critical: Processing outside the EU, for example via US clouds, is legally vulnerable under data protection law. In regulated sectors and the public sphere, it is often a disqualifying criterion.

  • Hallucinations are a compliance risk: Incorrect or fabricated information can violate liability and information obligations.

  • What to watch out for: Legal basis, EU hosting, DPA according to Art. 28, no training with your data, transparency labeling, deletion concept, and traceable answers.

What does “GDPR- and EU-AI-Act-compliant” mean for an AI chatbot?

An AI chatbot touches on two legal areas at once. It processes personal data such as names, requests, contact details, and chat histories, and therefore falls under the GDPR. At the same time, it is an AI system that interacts with natural persons, making it subject to the EU AI Act (Regulation (EU) 2024/1689).

Compliance therefore requires both together:

  • GDPR: lawful, transparent, and purpose-bound processing of personal data, data minimization, data subject rights, data processing agreements, and security of processing.

  • EU AI Act: risk-based obligations for the AI system, ranging from transparency and labeling to technical literacy requirements, governance, and human oversight.

Both frameworks interlock. A chatbot can be hosted in a technically GDPR-compliant manner and still violate the transparency requirements of the EU AI Act. Conversely, it can be correctly labeled as an AI and yet inadmissibly transfer data to a third country.

The EU AI Act 2026: The Timeline for Chatbots

The EU AI Act has been in force since August 2024 and takes effect in a phased approach. Three points are central for chatbots:

  1. Prohibited practices and AI literacy are among the obligations taking effect early. Manipulative or impermissible AI applications are banned; employees operating AI systems must have sufficient AI literacy (Art. 4).

  2. Transparency obligations (Art. 50) are the core for dialogue-oriented systems: users must be able to recognize that they are speaking with an AI and not a human.

  3. The stricter high-risk obligations take effect last. The Digital Omnibus (2026) adjusted requirements and deadlines; parts of these will only apply in stages up to 2027/2028.

Even if individual deadlines lie further in the future, 2026 is the year companies should align their chatbots. Those who only establish compliance by the final deadline will end up retrofitting privacy and transparency into a running system. This is more expensive and error-prone than a well-thought-out design from the start.

Is an AI Chatbot a High-Risk System?

In most cases, no. A chatbot that answers recurring service, HR, or sales questions does not make automated decisions about individuals in sensitive areas and is therefore not a high-risk system within the meaning of the EU AI Act.

However, the classification depends on the specific use case, and the operator is responsible for this (Art. 3 No. 4 EU AI Act). If you use a bot, for example, for pre-selecting job applications or for creditworthiness communication, the context of use can change the risk classification. Therefore, clarify the purpose before going live.

“AI must be traceable, controllable, and subject to effective human oversight.”

Dr. Maximilian Panzner, CTO and Co-Founder at Mercury.ai

The Three Pillars of an EU-AI-Act-Compliant Chatbot

A compliant chatbot rests on three pillars derived directly from the regulation:

1. Transparency (Art. 50). Users must recognize that they are interacting with an AI, for example through clear labeling and a highly visible bot icon. In the future, this will also include machine-readable metadata for AI-generated content and barrier-free accessibility according to WCAG.

2. AI Literacy (Art. 4). The people who operate and maintain the bot must understand what the system can do, where its limits lie, and when they need to intervene. AI literacy must be built continuously and remains an ongoing task.

3. Governance and Information Security. This is where the EU AI Act and GDPR (Art. 5, 28, 32) interlock: documented responsibilities, data processing agreements, technical and organizational measures, audit trails, and effective human oversight.

GDPR Checklist for AI Chatbots

These are the points every AI chatbot that processes personal data should fulfill:

  • Legal Basis (Art. 6): A legal basis must exist for every processing activity, usually legitimate interest or consent. Clarify on what basis chat histories are processed and stored.

  • Transparency and Information Obligations (Art. 13): Users must know which data is processed for what purpose. Privacy policy links belong directly inside the chat interface, accessible with a single click.

  • Data Minimization (Art. 5): The bot should only collect the data it actually needs for the request. “We store everything, maybe we'll need it” is not a permissible principle.

  • Data Processing Agreement (Art. 28): A data processing agreement (DPA/AVV) must be in place with the provider. Check the list of sub-processors. The shorter and the more localized to the EU, the easier the proof.

  • Data Location and Third-Country Transfer (Art. 44 et seq.): If data is transferred to a US provider, you need a robust transfer mechanism. Processing exclusively within the EU avoids this risk entirely.

  • Special Categories (Art. 9): If the bot processes health, religious, or other sensitive data, higher requirements apply. If in doubt, it should not collect such inputs in the first place.

  • Data Subject Rights: Inquiry, correction, and deletion must be practically executable, ideally with configurable deletion periods and the option for users to delete their own data.

  • No Unreviewed Automated Individual Decisions (Art. 22): Decisions with legal effects must not be made solely on an automated basis. An escalation path to a human is mandatory.

  • No Training with Your Data: If the content of your conversations is used to train external models, you lose control. Compliant solutions rule this out contractually and technically.

  • Data Protection Impact Assessment (Art. 35): A DPIA is required if a high risk is likely. A reputable provider will assist you with the necessary documentation.

Why US Cloud Chatbots Become a Compliance Risk

Many popular AI chatbots process data in US data centers or call the API of a US provider in the background. In terms of data protection, this is the most critical point: as soon as personal data enters a third country, you need a resilient transfer mechanism and carry the risk if its legal basis falls away.

For regulated industries and the public sector, the data location is frequently a dealbreaker. Data sovereignty by architecture solves the problem at its root: data that never leaves the EU does not raise the question of third-country transfer in the first place.

Therefore, pay attention to both levels: the hosting location and the operational data flows. A frontend hosted in Germany that requests a US API for every response is not data-sovereign. How data sovereignty can be achieved through architecture is explained in detail in our article on Chatbot Hosting in Germany.

Hallucinations Are Also a Compliance Issue

Compliance does not stop at data protection. If a chatbot invents information—such as contract terms, deadlines, or legal claims—this can violate information obligations and trigger liability. This is exactly what many companies observe when employees or customers use generic AI tools on their own: the answer sounds plausible, but is completely incorrect.

The cause lies in the architecture. A pure large language model chatbot generates answers based on probabilities. It calculates the most likely sequence of words without knowing the actual facts. A hybrid architecture, on the other hand, separates facts from formulation. The facts originate exclusively from verified, approved sources, while the generative AI only handles the linguistic delivery. If the system cannot find a proven answer, it hands the case over to a human in a controlled manner.

This approach significantly reduces the risk of hallucinations and makes every response traceable to its source. This is a direct contribution to transparency and human oversight as required by the EU AI Act. You can read about how this works technically under Mercury Intelligence and in our Knowledge Hub.

Illustration zu DSGVO und EU AI Act Anforderungen für KI-Chatbots

How Mercury.ai Implements GDPR and EU AI Act Compliance

Mercury.ai is the conversational AI platform from Germany, designed to meet the requirements of both the GDPR and the EU AI Act (Regulation (EU) 2024/1689). The main components include:

  • Hosting exclusively in Germany (AWS Frankfurt, eu-central-1). End-user data is processed exclusively there, without third-country transfer. Encryption is applied in transit and at rest, key management via AWS KMS and HSM, with customer-managed keys available as an option.

  • A single sub-processor (Amazon Web Services, German branch) keeps the processing chain short and the DPA verification simple.

  • European, self-hosted models. Mercury.ai uses licensed, self-hosted, and fine-tuned Mistral models. There are no API calls to external providers; the data remains in Germany under full control.

  • No training with customer data, no cross-client learning. Answers are generated exclusively from your verified, secure sources; open-world knowledge is excluded.

  • Hybrid AI against hallucinations. Our orchestration of models separates facts from formulation, checks sources and permissions, and hands over to a human if no source is available. The risk of hallucination is significantly reduced, and every answer remains traceable back to its source.

  • Security and Governance. Role and tenant separation, multi-factor authentication, full audit logging, regular penetration tests, and protection against prompt injection. The data centers used are ISO 27001 certified; Mercury.ai's operations are aligned with ISO 27001 standards.

  • EU AI Act compliance according to the three-pillar model of transparency, AI literacy, and governance, documented in our EU AI Act Whitepaper.

The fact that this model is viable even in highly regulated environments is proven by Volkswagen Bank: they use Mercury.ai to automate recurring customer inquiries 24/7, in an industry where privacy and traceability are non-negotiable.

You can read about our approach to the EU AI Act in our dedicated EU AI Act Whitepaper.

7 Steps to a Compliant Chatbot: The Provider Checklist

Ask any chatbot provider these seven questions before making a decision:

  1. Where is the data processed, and where does the bot send data during operation? The answer must be: exclusively in the EU, without third-country APIs.

  2. Who is listed as a sub-processor in the DPA? The shorter and more EU-centric the list is, the better.

  3. Are our conversations used to train external models? The only acceptable answer is: no, contractually and technically excluded.

  4. How does the bot identify itself as an AI? Art. 50 requires that users are able to recognize it.

  5. Where do the answers come from, and are they traceable to the source? Source bounding is the most effective protection against hallucinations.

  6. How does the handover to a human work? There must be a clear escalation path when the bot reaches its limits.

  7. What documentation do we receive for DPIA, DPA, and EU AI Act verification? A professional provider offers this actively.

Anyone who receives clear, verifiable answers to these seven questions has the foundation for a chatbot that meets both the GDPR and the EU AI Act in 2026.

Frequently Asked Questions (FAQ)

Is an AI chatbot automatically a high-risk system under the EU AI Act?
No. A chatbot that answers recurring service, HR, or sales questions and does not make automated decisions about individuals in sensitive areas is generally not a high-risk system. However, the operator is responsible for classifying the specific use case (Art. 3 No. 4 EU AI Act).

Do I have to inform users that they are chatting with an AI?
Yes. The transparency obligation in Art. 50 of the EU AI Act requires that users can recognize they are interacting with an AI system and not a human, for example through clear labeling and a recognizable bot icon.

Where can the data of a GDPR-compliant chatbot be stored?
Personal data should be processed within the EU. A transfer to third countries like the US is only permitted under a robust transfer mechanism and remains legally vulnerable. Exclusive processing in the EU, for example in Frankfurt, avoids this risk entirely.

Is a generic AI tool like ChatGPT GDPR-compliant for customer service?
Generic, publicly hosted AI tools frequently process inputs outside the EU and offer no control over data location, deletion, or training usage. For processing personal customer data, they are generally unsuitable without additional contractual and technical safeguards. An EU-hosted, source-bound platform is the secure choice here. For more details on ChatGPT, read our article: Is ChatGPT in Customer Service GDPR-compliant?.

Do I need a Data Protection Impact Assessment (DPIA) for a chatbot?
A DPIA is required if the processing is likely to result in a high risk to the rights and freedoms of natural persons (Art. 35 GDPR). Whether this is the case depends on the use case and the categories of data processed. A professional provider will support you with the necessary documentation.

Who is liable if the chatbot gives incorrect information?
The deploying company acts as the responsible party toward the customer. This is why an architecture that binds answers to verified sources, significantly reduces the risk of hallucination, and hands over to a human in case of uncertainty is critical before incorrect information is provided.

Visualisierung eines konformen KI-Chatbots mit Quellenbindung und Datenschutzkontrolle

Conclusion: Compliance Belongs in the Architecture From the Start

In 2026, AI chatbots must meet two regulatory frameworks simultaneously: the GDPR and the EU AI Act. Both can be complied with most reliably when data location, source bounding, transparency, and human oversight are part of the architecture from the very beginning. Those who consistently measure providers against the checklist above will make a decision that remains viable for the later deadlines of the EU AI Act.

Would you like to know what a GDPR- and EU-AI-Act-compliant chatbot looks like for your business? Talk to us or download our EU AI Act Whitepaper.

About the Author: Dr. Maximilian Panzner is CTO and Co-Founder of Mercury.ai. He holds a PhD in Computer Science from the CITEC Institute at Bielefeld University, where he researched multimodal machine learning and intelligent interaction systems. He has been working on artificial intelligence, human-machine interaction, and dialogue-oriented enterprise AI platforms for more than 20 years.

Discover related posts
Four black dots on a white background as a symbol for interaction or user interface at mercury.ai

Talking Better. Start with Mercury now.

Take your AI communication to the next level.

Four black dots on a white background as a symbol for interaction or user interface at mercury.ai

Talking Better. Start with Mercury now.

Take your AI communication to the next level.