Cybersécurité

Tout chatbot en Europe doit désormais se déclarer IA — ou son créateur paie 15 millions d’euros

Susan Hill

Any chatbot or AI system that converses with European users must now identify itself as artificial intelligence. The requirement covers ChatGPT, Gemini, and Claude. It covers automated customer service bots, AI writing tools, and any software that simulates human conversation. The fine for non-compliance is up to €15 million or 3 percent of a company’s global annual turnover — whichever is higher. The rule is not a proposal or a pilot. It is law.

The requirement comes from Article 50 of the EU Artificial Intelligence Act, which entered into force on August 2, 2026. The article covers three distinct obligations: chatbots must disclose that the user is interacting with an AI system, deepfake content must be labeled as AI-generated, and AI systems that analyze emotions in workplace or education settings must disclose their operation. Disclosures must be clear, timely, and appropriate — though the regulation leaves implementation format to the companies.

The scope is broader than it sounds. European regulators have confirmed that the law applies not just to companies headquartered in the EU but to any service that reaches EU users — which means Meta’s AI assistant, Apple‘s Siri, LinkedIn’s AI job coach, and thousands of customer service deployments run by companies with European customers all fall under the requirement. The €15 million ceiling applies to smaller violations; the 3 percent of global turnover floor kicks in when the company is large enough that €15 million would not constitute a real deterrent.

Enforcement in the EU typically moves slowly. National AI authorities, whose budgets range from limited to nonexistent, are responsible for monitoring compliance. The General Data Protection Regulation, passed in 2018, went largely unenforced for nearly two years before the first major fines were issued. AI Act enforcement is expected to follow a similar pattern — guidance from national regulators before formal action. The Article 50 transparency rules are among the simpler provisions to enforce: compliance requires only a visible disclosure, not an audit of system architecture.

Whether a mandatory disclosure meaningfully changes how European users relate to AI is an open question. Research on analogous requirements — including cookie consent banners mandated by GDPR — suggests that notices improve legal clarity more than they shift user behavior. A chatbot that opens every conversation with ‘I am an AI’ and then proceeds to be indistinguishable from a human satisfies the legal requirement without resolving the deeper question of what adequate AI transparency actually means in practice.

The harder provisions of the AI Act remain on hold. The Digital Omnibus package, passed in June 2026, moved the Annex III compliance deadline — covering high-risk AI systems used in hiring, credit scoring, biometric identification, and law enforcement — from August 2026 to December 2027. Companies in the most commercially sensitive sectors have sixteen more months to prepare. Article 50 is the consumer-facing layer that went live while the rules that matter most to industry wait.

The EU is the first major jurisdiction to make AI self-disclosure a statutory requirement rather than a design recommendation. Equivalent rules are under discussion in California and the United Kingdom but have not passed into law. For the 450 million people inside the EU, the question of whether they are talking to a person or a machine now has a legal answer — how consistently that answer reaches them will depend on enforcement that has not yet started.

Étiquettes: , , , , ,

Discussion

Il y a 0 commentaire.