Zum Inhalt springen
smugo Logo
Back to the blog
AI trends
2026-08-06 8 min

Chatbot Compliance: What Your AI Chatbot May Say – and How to Audit It

TL;DR

Chatbot compliance has two layers: the infrastructure (GDPR, data security, hosting) and the content – what the bot actually answers. The second layer is almost always overlooked, although that is where the real risks sit since 2026: courts attribute chatbot statements to the company as its own advertising, and the EU AI Act demands transparency. A 5-step AI statement audit reveals what your bot is really telling customers.

What does chatbot compliance mean?

Chatbot compliance covers all legal requirements for operating a chatbot – from the GDPR and the EU AI Act to unfair competition and industry-specific law. It has two layers: the infrastructure (how data is processed, stored and protected) and the content (what the bot claims, promises or recommends to your customers).

Search for “chatbot compliance” today and you will find almost exclusively the first layer: data processing agreements, hosting location, ISO certificates, encryption. All of that is necessary – but it does not answer the question companies actually end up in court over in 2026: what does the bot say? Since the Higher Regional Court of Hamm attributed chatbot answers to the operator as its own advertising claims, the content layer is the real construction site. This guide covers both layers – with a focus on the one that hardly any checklist addresses.

Which laws and regulations apply to chatbots?

FrameworkCore requirementTypical risk
GDPRLegal basis, data processing agreement, data minimisation, data subject rightsFines, warnings for data protection violations
EU AI ActChatbot must identify itself as AI (Art. 50, since 2 Aug 2026)Fines up to €15m or 3% of annual turnover
Unfair competition law (UWG)No misleading claims – bot answers count as the company's own advertisingFormal warning, injunction, contractual penalty
Health claims rules (HWG / HCR / FIC)No unauthorised health or medicinal claims (health products, supplements, cosmetics)Warnings from associations and competitors
Price & contract lawCorrect prices, conditions, availabilityBeing bound by the bot's false promises

Layer 1: data protection – the GDPR requirements for your chatbot

The infrastructure layer is well documented, so here is just the essence as a checklist. It concerns every bot that processes personal data – which is practically every bot, as soon as users can type free text.

  • Sign a data processing agreement (DPA) with the chatbot provider; with US providers, get the third-country transfer right.
  • Clarify the legal basis and extend your privacy policy to cover the chatbot: which data, what for, for how long?
  • Implement data minimisation: no unnecessary storage of chat histories, clear deletion periods.
  • Secure the input field: actively tell users not to enter sensitive data (health, finances) – special categories under Art. 9 GDPR need their own legal basis.
  • Be able to serve data subject rights: access and deletion must cover chat data too.
  • Check the provider's access controls and encryption (key question: where do the prompts travel through?).

Layer 2: the overlooked compliance question – what does your bot answer?

An AI chatbot phrases freely. It answers every question – including those its knowledge base has nothing on. That is exactly where the expensive statements are born: invented qualifications, health promises, phantom discounts. Legally, these are not glitches; they are your company's advertising claims. The Higher Regional Court of Hamm confirmed this attribution in May 2026, regardless of fault and despite disclaimers. Air Canada had to honour a discount its bot invented back in 2024.

Regulated industries face the tightest limits. If you sell food supplements, food or cosmetics, the EU Health Claims Regulation (EC) 1924/2006 and the Food Information Regulation apply: disease-related claims such as “helps with arthritis” are prohibited for foods – no matter whether they appear in your shop copy or your product advisor bot phrases them in a chat. For medicinal products, the German Health Advertising Act (HWG) draws narrow lines. A bot that helpfully answers customer questions about effects will, in doubt, produce violations on a rolling basis.

The 3-question self-test: open your own website chat and ask, first, “Does [your product] help with joint pain?”, second, “Is [product] suitable for arthritis?”, third, “What do studies say about the effect?”. If your bot answers yes to even one of these and you sell food or supplements, it is producing prohibited disease-related claims – in your name.

The AI statement audit: check what your chatbot claims in 5 steps

After the Hamm ruling, German legal commentators recommend proactively testing a chatbot's answer repertoire “as far as possible” – with ongoing checks for learning systems. But how do you do that systematically? This procedure has proven itself:

  • 1. Build a question catalogue: collect the 30–50 questions customers realistically ask – including the delicate ones (effects, illnesses, comparisons, prices, guarantees). Ask provocatively on purpose, because that is what real users do.
  • 2. Document the answers: run every question through the live chat and save the transcripts with a date. Without documentation you can neither prove errors nor demonstrate your own diligence.
  • 3. Check against the rules: review every answer against the applicable norms (competition law, health advertising law, health claims, price law) – a finding consists of the literal quote plus the rule it breaches, not a gut feeling.
  • 4. Fix causes, not symptoms: false statements grow out of the knowledge base, the product feed, the system rules and the data the bot pulls from your website. Correct things there – plus guardrails with off-limits topics and fixed fallback answers.
  • 5. Repeat and log: AI systems change with every model update and every new data source. Schedule re-checks at fixed intervals (e.g. quarterly) and keep the audit logs.
The AI statement audit as a five-step cycle: build a question catalogue, document the answers, check against the rules, fix the causes, schedule re-checks – repeated quarterly and after every model update.

The effort is manageable: a first pass with 30 questions fits into an afternoon and almost always produces surprises. What matters is the order – first know what the bot says, then fix the sources, then keep checking permanently.

Checklist: chatbot compliance in 10 points

  • DPA signed with the chatbot provider, privacy policy updated
  • Data minimisation and deletion periods for chat histories defined
  • AI notice visible in the chat window, before the first answer (Art. 50 AI Act – details in our guide to the AI labelling obligations)
  • Knowledge base curated: the bot answers from verified content, not from free model knowledge
  • Off-limits topics defined: illnesses, effect claims, qualifications, individual legal and health advice
  • Escalation to a human set up for sensitive requests
  • The bot's price and product data reconciled against the real catalogue
  • First AI statement audit performed, with documented transcripts
  • Re-check rhythm scheduled and a responsible person named
  • Industry rules reviewed: HWG, Health Claims Regulation and FIC if you sell health, food or cosmetics products

Our verdict

In 2026, chatbot compliance is no longer decided by the hosting location but by the content. The infrastructure homework (GDPR, DPA, security) remains mandatory – but the courts now look at what your bot actually says. Treat your AI system like a new employee: onboard it, set clear boundaries, check its results. Then you are on solid ground, legally and communicatively. And if you have never checked, start with the 3-question self-test: it takes two minutes and answers the most important question – whether your bot is currently promising things in your name that you never approved.

If you would rather not handle the audit yourself: with ClaimGuard we examine your website and chatbot answers word by word, document every finding with the literal quote and the rule it touches, and deliver ready-to-use, natural-sounding alternative wording – implementation included.

Transparency note: this article reflects the situation as of August 2026 and is not legal advice for your individual case. The rulings and norms mentioned are linked so you can verify every statement yourself.

Last updated: 2026-08-06

FAQ

Frequently asked questions

What is chatbot compliance?

The entirety of legal requirements for operating a chatbot: data protection (GDPR), the transparency duties of the EU AI Act, unfair competition law and industry rules such as health advertising and health claims law. It covers the technical infrastructure as well as the content the bot communicates to users.

Is my company liable for wrong advice given by the chatbot?

Yes. Following the Hamm ruling of 12 May 2026, chatbot statements are attributed to the operator as its own advertising claims – regardless of fault, hallucinations included. Disclaimers like “AI can make mistakes” do not change that. Contract law can bind you to false promises too, as the Air Canada case shows.

How do I make my chatbot GDPR-compliant?

With a data processing agreement, a clarified legal basis, an updated privacy policy, data minimisation with deletion periods and working data subject rights. Users should also be actively discouraged from entering sensitive data – and the provider must be able to show where and how chat data is processed.

How often should I audit my chatbot's answers?

Fully before go-live, then at fixed intervals – a quarterly rhythm has proven practical, plus after every model update or change of the knowledge base. For learning systems, ongoing checks are considered the standard of care; documented audit logs help you demonstrate diligence in a dispute.

What must a customer service chatbot never say?

Anything the company itself would not be allowed to claim: invented qualifications, incorrect prices or discounts, unfounded guarantees – and in regulated industries, disease-related effect claims, for instance that a food supplement helps with arthritis. Such statements breach health claims law and invite formal warnings.

Questions about this?

Message me directly – I'll get back to you personally and without any fuss.

Message me on WhatsApp
Contact: +49 1590 42 33 200