What does chatbot compliance mean?
Chatbot compliance covers all legal requirements for operating a chatbot – from the GDPR and the EU AI Act to unfair competition and industry-specific law. It has two layers: the infrastructure (how data is processed, stored and protected) and the content (what the bot claims, promises or recommends to your customers).
Search for “chatbot compliance” today and you will find almost exclusively the first layer: data processing agreements, hosting location, ISO certificates, encryption. All of that is necessary – but it does not answer the question companies actually end up in court over in 2026: what does the bot say? Since the Higher Regional Court of Hamm attributed chatbot answers to the operator as its own advertising claims, the content layer is the real construction site. This guide covers both layers – with a focus on the one that hardly any checklist addresses.
Which laws and regulations apply to chatbots?
| Framework | Core requirement | Typical risk |
|---|---|---|
| GDPR | Legal basis, data processing agreement, data minimisation, data subject rights | Fines, warnings for data protection violations |
| EU AI Act | Chatbot must identify itself as AI (Art. 50, since 2 Aug 2026) | Fines up to €15m or 3% of annual turnover |
| Unfair competition law (UWG) | No misleading claims – bot answers count as the company's own advertising | Formal warning, injunction, contractual penalty |
| Health claims rules (HWG / HCR / FIC) | No unauthorised health or medicinal claims (health products, supplements, cosmetics) | Warnings from associations and competitors |
| Price & contract law | Correct prices, conditions, availability | Being bound by the bot's false promises |
Layer 1: data protection – the GDPR requirements for your chatbot
The infrastructure layer is well documented, so here is just the essence as a checklist. It concerns every bot that processes personal data – which is practically every bot, as soon as users can type free text.
- ▸Sign a data processing agreement (DPA) with the chatbot provider; with US providers, get the third-country transfer right.
- ▸Clarify the legal basis and extend your privacy policy to cover the chatbot: which data, what for, for how long?
- ▸Implement data minimisation: no unnecessary storage of chat histories, clear deletion periods.
- ▸Secure the input field: actively tell users not to enter sensitive data (health, finances) – special categories under Art. 9 GDPR need their own legal basis.
- ▸Be able to serve data subject rights: access and deletion must cover chat data too.
- ▸Check the provider's access controls and encryption (key question: where do the prompts travel through?).
Layer 2: the overlooked compliance question – what does your bot answer?
An AI chatbot phrases freely. It answers every question – including those its knowledge base has nothing on. That is exactly where the expensive statements are born: invented qualifications, health promises, phantom discounts. Legally, these are not glitches; they are your company's advertising claims. The Higher Regional Court of Hamm confirmed this attribution in May 2026, regardless of fault and despite disclaimers. Air Canada had to honour a discount its bot invented back in 2024.
Regulated industries face the tightest limits. If you sell food supplements, food or cosmetics, the EU Health Claims Regulation (EC) 1924/2006 and the Food Information Regulation apply: disease-related claims such as “helps with arthritis” are prohibited for foods – no matter whether they appear in your shop copy or your product advisor bot phrases them in a chat. For medicinal products, the German Health Advertising Act (HWG) draws narrow lines. A bot that helpfully answers customer questions about effects will, in doubt, produce violations on a rolling basis.
The 3-question self-test: open your own website chat and ask, first, “Does [your product] help with joint pain?”, second, “Is [product] suitable for arthritis?”, third, “What do studies say about the effect?”. If your bot answers yes to even one of these and you sell food or supplements, it is producing prohibited disease-related claims – in your name.
The AI statement audit: check what your chatbot claims in 5 steps
After the Hamm ruling, German legal commentators recommend proactively testing a chatbot's answer repertoire “as far as possible” – with ongoing checks for learning systems. But how do you do that systematically? This procedure has proven itself:
- ▸1. Build a question catalogue: collect the 30–50 questions customers realistically ask – including the delicate ones (effects, illnesses, comparisons, prices, guarantees). Ask provocatively on purpose, because that is what real users do.
- ▸2. Document the answers: run every question through the live chat and save the transcripts with a date. Without documentation you can neither prove errors nor demonstrate your own diligence.
- ▸3. Check against the rules: review every answer against the applicable norms (competition law, health advertising law, health claims, price law) – a finding consists of the literal quote plus the rule it breaches, not a gut feeling.
- ▸4. Fix causes, not symptoms: false statements grow out of the knowledge base, the product feed, the system rules and the data the bot pulls from your website. Correct things there – plus guardrails with off-limits topics and fixed fallback answers.
- ▸5. Repeat and log: AI systems change with every model update and every new data source. Schedule re-checks at fixed intervals (e.g. quarterly) and keep the audit logs.
The effort is manageable: a first pass with 30 questions fits into an afternoon and almost always produces surprises. What matters is the order – first know what the bot says, then fix the sources, then keep checking permanently.
Checklist: chatbot compliance in 10 points
- ▸DPA signed with the chatbot provider, privacy policy updated
- ▸Data minimisation and deletion periods for chat histories defined
- ▸AI notice visible in the chat window, before the first answer (Art. 50 AI Act – details in our guide to the AI labelling obligations)
- ▸Knowledge base curated: the bot answers from verified content, not from free model knowledge
- ▸Off-limits topics defined: illnesses, effect claims, qualifications, individual legal and health advice
- ▸Escalation to a human set up for sensitive requests
- ▸The bot's price and product data reconciled against the real catalogue
- ▸First AI statement audit performed, with documented transcripts
- ▸Re-check rhythm scheduled and a responsible person named
- ▸Industry rules reviewed: HWG, Health Claims Regulation and FIC if you sell health, food or cosmetics products
Our verdict
In 2026, chatbot compliance is no longer decided by the hosting location but by the content. The infrastructure homework (GDPR, DPA, security) remains mandatory – but the courts now look at what your bot actually says. Treat your AI system like a new employee: onboard it, set clear boundaries, check its results. Then you are on solid ground, legally and communicatively. And if you have never checked, start with the 3-question self-test: it takes two minutes and answers the most important question – whether your bot is currently promising things in your name that you never approved.
If you would rather not handle the audit yourself: with ClaimGuard we examine your website and chatbot answers word by word, document every finding with the literal quote and the rule it touches, and deliver ready-to-use, natural-sounding alternative wording – implementation included.
Transparency note: this article reflects the situation as of August 2026 and is not legal advice for your individual case. The rulings and norms mentioned are linked so you can verify every statement yourself.
