This is not legal or tax advice. The layer implements controls. You and your counsel decide what applies to your business.

2 December 2026 · 1 January 2027

Chatbot compliance layer

Disclosure, age assurance, a crisis protocol and the log the regulator asks for, dropped into the bot you already run.

Two dates changed what a customer-facing chatbot has to do. The EU AI Act transparency rules apply from 2 August 2026, and generative systems that were already on the market have until 2 December 2026 to mark their output in a machine-readable format. Colorado's Chatbot Safety Act puts its duties on operators from 1 January 2027, with the first report to the Attorney General due 1 July 2027. Most of the tools that launched this summer scan a site and hand you a finding. This one installs the fix.

What the law actually says

Four clauses, quoted rather than summarised.

Each block names the clause it came from. The full source list is at the bottom of this page.

Article 50(1)
Applies from 2 August 2026

The person has to know it is an AI

Providers must make sure a person knows they are talking to an AI system. The clause requires systems intended to interact directly with natural persons to be designed so those persons are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person.

This is the one that catches almost every support bot, booking bot and WhatsApp assistant with EU users.

Article 50(2)
Pre-existing systems by 2 December 2026, under Article 111(4) as inserted by Regulation (EU) 2026/1744

Generated output has to be marked

Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and detectable as artificially generated or manipulated. A system placed on the market before 2 August 2026 has until 2 December 2026. That deadline is Article 111(4) of Regulation (EU) 2024/1689, and Article 111(4) is not in the 2024 text as published: it was added by Regulation (EU) 2026/1744, the Digital Omnibus on AI, at Article 1, point (39)(b), OJ L, 2026/1744, 24 July 2026.

Read the role carefully, and read it off the statute. Article 3(3) makes you a provider if you place the AI system on the market or put it into service under your own name or trademark. It does not turn on who built the model. So if you assemble a chat system, put it in front of users under your own name or brand, and run it on a third-party API, you are arguably the provider of that system and the deployer of the model inside it at the same time, and Article 50(2) is on the table. You are a deployer alone only where the assistant reaches your users under somebody else's name; then your obligations are 50(1) and, if you publish deepfakes or AI-written text on matters of public interest, 50(4).

It is a judgement call, not a settled one. We put the determination in writing as part of the install, with the clause quoted and the reasoning recorded, because getting it wrong in either direction costs money and the expensive direction is the one where you are told you are clear and do nothing.

Article 50(5)
Same clock as 50(1)

Clearly, and at the first interaction

The information has to reach the person in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and has to meet the applicable accessibility requirements.

HB26-1263
Duties from 1 January 2027, first report due 1 July 2027

Colorado Chatbot Safety Act

An operator of a conversational AI service has to estimate the age of users, disclose that the service is AI, keep minors away from sexual content and simulated emotional dependence, run a suicide and self-harm protocol that refers users to a crisis service provider (explicitly not a law enforcement agency), avoid presenting outputs as equivalent to a licensed professional, and file an annual report with the Attorney General.

The disclosure has three parts, and the third is the one implementations forget: at the start of the first interaction each day, at least once every three hours in a continuous interaction or as a persistent visible disclosure, and again whenever the user asks whether they are talking to a human.

The honest scope check

Most small-business support bots are exempt in Colorado and still covered by EU Article 50(1).

Colorado's definition of a conversational AI service carves out, among others, a program primarily designed to provide commerce-related or transactional assistance, including product or service recommendations, shopping, ordering, payments, delivery, returns, customer support, or customer service. So the answer for a typical shop or clinic bot is: yes for the EU disclosure, no for Colorado. You get told that, rather than sold a Colorado module you do not need. The scope check is a function in the package, it names the exact clause it relied on, and you get the output in writing.

Carved out of Colorado
  • Programs primarily designed for commerce or transactional assistance: recommendations, shopping, ordering, payments, delivery, returns, customer support and customer service
  • Narrow, single-topic bots that cannot produce sexually explicit output and cannot hold a conversation about suicide or self-harm
  • Business-productivity tools and internal-only tools
  • Video game and theme park features
  • HIPAA-covered entities
  • School tools that do not simulate emotional companionship
Lands inside Colorado
  • >Open-domain assistants
  • >Companion and roleplay products
  • >Anything that will hold a conversation about how someone is feeling
  • >Anything marketed to consumers as a general chat partner
In-scope check

Six questions. Answer them and you know where you stand.

Send these six answers and one bot URL, and the scope determination comes back with the clauses cited, at no charge.

  1. 01Do EU users reach the bot?
  2. 02Is it obvious to a reasonable user that they are talking to a machine, before they say anything?
  3. 03Do you put this chatbot in front of users under your own name or brand? Three answers, not two: somebody else's assistant carries their name (deployer), you built or host the generating system under your name (provider), or you assembled and branded the chat system and the model behind it is a third party's (both, and Article 50(2) is engaged).
  4. 04Does the bot publish generated text or media to the public, or produce deepfakes?
  5. 05Do Colorado users reach the bot, and is it available to the general public?
  6. 06Is the bot doing commerce or a single narrow task, and can it be steered into sexual content or a conversation about self-harm?

Question 6 is the one that decides Colorado for most small businesses.

What it costs

Per bot, or per agency.

If NeuraScale builds you a bot for EU users, the layer is part of the build rather than an upsell. These prices are for retrofits and for bots somebody else built.

Start here
Install
EUR 490
per bot, one time

The controls installed into the bot you already run, in an afternoon, starting with a written answer about which of them you actually owe.

  • Scope determination for both jurisdictions, with the clause and source URL for every yes and every no, signed and dated
  • Disclosure wired in: first message of the day, the three-hour rule inside a long conversation or a persistent banner, and an answer when the user asks whether this is a human
  • Age assurance gate where it applies: a pluggable estimator, the six age categories the Colorado draft rules name, and a default that refuses to record a user as an adult on an inconclusive result
  • Crisis protocol: detection, a referral response carrying a crisis service provider you have verified, escalation for repeated or severe indicators, a human handoff hook, and a log entry on every one
  • Audit log: a table in your own database, no message content stored by default, plus the query that produces the fields the Colorado annual report asks for
  • Synthetic content marking helpers for text, plus the hook for image and audio if you have a manifest signer
  • A short policy pack: your disclosure texts, the escalation policy, the retention statement, and the annual report template with the field list
Monitoring
EUR 29
per month, per bot, on top of the install

For bots that keep taking traffic after the install call ends, while the Colorado rules are still moving.

  • Monthly log summary
  • An end-to-end test of the crisis path
  • An update when Colorado or the Commission publishes new guidance
Agency licence
EUR 1,500
flat, unlimited installs by the agency

For agencies who built the bots and are now the ones being asked about them.

  • Unlimited installs by your team
  • Co-branded policy pack
  • One hour of support per month

The Colorado rules are still in a comment period that runs to 26 October 2026, so the annual report fields can still move. That is what the monthly tier is for. English disclosure strings ship ready. German and French strings ship marked for native review before they go live.

Never offered

What this is not, in writing.

Legal advice, or any opinion on what applies to your business
Any claim that a bot is compliant or certified under the EU AI Act
A scanner or an audit report
Biometric identification
Content moderation beyond the crisis path
High-risk AI system conformity work (Annex III)
General-purpose AI model obligations
Filing your Colorado annual report for you
FAQ

The questions that decide it.

No, and nobody can sell you that. The layer implements controls and writes down which obligations the scope determination says apply to you, with the clause and the source for each. Whether those controls satisfy your duties is a question for you and your counsel. There is no certification for a chatbot under the EU AI Act, so treat anyone offering one accordingly.
Sources

All fetched 6 September 2026. Where an article number or a rule reference appears above, it is cited as these sources state it: check the official text before you rely on it.

Free scope determination

Send one bot URL and the six answers.

You get the scope determination back with the clauses cited, at no charge. If it turns out you are in scope, the install is EUR 490 and takes an afternoon. Agencies: say how many bots and ask about the licence.

This is not legal or tax advice. The layer implements controls. You and your counsel decide what applies to your business.

By submitting, you agree to be contacted about your inquiry. No sales calls, no spam. 18-24h typical reply.

Prefer email or WhatsApp? omar@neurascale.org or +20 150 047 7334. Cairo (GMT+2), which covers EU mornings and US afternoons.

The two dates

2 December 2026, then 1 January 2027.

Marking for pre-existing generative systems, then the Colorado duties. The scope determination is free and tells you which of them is actually yours.

18–24h reply · Cairo + EU hours · honest scoping