A chatbot's first message should say that it is an automated AI assistant, what it can help with, and how to reach a person. If you sell to customers in the EU, the AI Act's Article 50 has required people to be told they're interacting with AI, clearly and at first contact, since 2 August 2026, unless it's obvious.
Disclosure is cheap and mostly about expectations. Customers who know they're talking to software phrase questions simply, forgive a limited answer, and ask for a person when they need one. Customers who think they're talking to a person take its answers as the firm's word, and that is where complaints about chatbots come from.
What the first message has to cover
Four things, in about 40 words:
- What it is. "An automated assistant" or "an AI assistant". Plain words, not "virtual concierge" or "digital team member".
- What it can do. Two or three tasks, so customers don't bring it questions it can't answer.
- How to reach a person, and when. A word to type, a button, or a phone number, plus your hours.
- What it can't do, if you're in a sector where that matters: no advice, no cover decisions, no quotes.
A filled-in example for an illustrative insurance broker:
Hi, I'm [Broker name]'s automated assistant. I can find your policy documents, renewal dates and claim phone numbers. I can't confirm what your policy covers; a broker can. Type "person" at any time, or call [number], 9am to 5.30pm weekdays.
That is 45 words and it does all four jobs. Your wider website disclosure, covering AI use beyond the chatbot, is a separate document; writing an AI disclosure statement for your website covers it. The chat greeting is the part customers actually read.
What Article 50 of the EU AI Act requires, and from whom
If you have customers in the EU, three parts of the Act matter for chatbots. This is a practical summary, not legal advice; check your own position with an adviser.
- The duty. Article 50(1) requires that AI systems intended to interact directly with people are designed and developed so the people concerned are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person given the context. These transparency duties were not deferred when other parts of the Act were, and have applied since 2 August 2026.
- The manner. Article 50(5) says the information must be given in a clear and distinguishable manner at the latest at the time of the first interaction, and must meet accessibility requirements. A greeting message meets that; a line in your terms of use doesn't.
- The penalty. Breaches of Article 50 can bring fines of up to EUR 15 million or 3% of worldwide annual turnover; for small and medium-sized businesses, whichever of the two is lower applies.
Formally, Article 50(1) falls on the provider, which the Act defines as whoever develops an AI system, or has one developed, and puts it into service under its own name or trademark. A business that builds its own chatbot on a model and runs it on its website under its own name may well be a provider. A business using a vendor's chatbot product is usually a deployer, with the vendor as provider. In practice the distinction matters less than it looks, because the greeting text is almost always yours to write. Write it to disclose, whichever role you have.
Don't lean on the "obvious" exception. A chat window on a website with a friendly name and a photo is not obviously software to most people. Other places have their own rules on bots, particularly around sales and persuasion, so if you sell elsewhere, ask your adviser what applies there. Whether to tell customers about AI more broadly, beyond chat, is covered in should you tell customers you use AI.
Six opening messages, rated
Illustrative greetings of the kind small businesses actually run, from worst to best:
| Opening message | Problem | Verdict |
|---|---|---|
| "Hi there! How can I help today?" | No disclosure at all | Fails |
| "Hi, I'm Sarah from [Firm]. How can I help?" (with a stock photo) | Implies a person; actively misleading | Fails |
| "Hi! This chat may use automated technology. See our terms." | Vague and pushed to another page | Weak |
| "This service uses an artificial intelligence system as defined under applicable law. By continuing you agree to our terms." | Clear but cold, with no route to a person | Weak |
| "Hi, I'm [Firm]'s automated assistant. I can answer questions about our services and book a call. Type 'person' to reach our team." | Clear, scoped, with an exit | Good |
| The one above, plus: "I can't give advice about your situation; our team can, on a call." | Also sets the limit that matters in advice sectors | Best for regulated firms |
The second row is the one to watch for, because it often isn't deliberate. A chatbot platform's default template or a designer's mock-up gives the bot a human name and face, and nobody questions it before launch.
Naming the assistant without implying a person
A realistic mistake shows why names matter. An illustrative mortgage adviser launched a website assistant called "Emma", with a smiling stock photo, because the platform's demo used one. Within weeks, transcripts showed customers writing "thanks Emma, so I'm approved then?" after the bot had explained, correctly, how lenders assess applications in general. Customers had read general information as a personal answer from an adviser called Emma. Two complaints followed, both from people who believed they'd been told they would get a mortgage.
The fix took an afternoon: the assistant became "[Firm name] Assistant", the photo became a simple chat icon, the greeting opened with "I'm an automated assistant, not an adviser", and a line was added to the instructions about questions on borrowing (see the sector lines below). Afterwards, questions like "are you a real person?" in the transcripts dropped from several a week to one or two a month, which is the best evidence the disclosure had landed.
Rules for naming that avoid the problem:
- Use the business name plus "assistant", or a clearly non-human name.
- Use an icon or logo, never a photo of a person or a realistic generated face.
- Keep human names for humans. When a person takes over, their real first name is part of what tells the customer something has changed.
When a customer asks "Am I talking to a real person?"
Some customers will ask, however clear the greeting. The assistant must answer truthfully every time, and a poorly instructed bot often dodges. An illustrative exchange with an assistant that had no instruction on the point:
Customer: Am I talking to a real person?
Assistant: I'm here to help with anything you need! What can I
do for you today?
That answer isn't a lie, but it is evasive, and to a customer who asked directly it reads like one. The remedy is an explicit line in the assistant's instructions:
If anyone asks whether you are a person, a bot or AI, say
plainly that you are an automated AI assistant, then offer to
connect them with a member of the team and give the hours.
With that line in place the same question produced: "No, I'm an automated assistant. I can pass you to a member of our team, who are available 9am to 5.30pm on weekdays, or I can book you a call." Test the question in several phrasings ("is this a bot?", "are you human?", "who am I talking to?") before launch, because instructions sometimes catch one wording and miss another.
A small law firm's chat, message by message
An illustration of a complete set-up. A six-lawyer firm runs a website assistant to handle out-of-hours enquiries: about 60 conversations a week, most arriving in the evening. The assistant's job is to collect enquiry details and book initial calls, not to answer legal questions. How that intake flow works end to end is covered in AI client intake for law firms; here are the disclosure points in order.
- Greeting: "Hi, I'm [Firm]'s automated assistant. I can take details of your enquiry and book a call with one of our lawyers. I can't give legal advice about your situation; a lawyer can, on the call. Type 'person' at any time and we'll get back to you the next working morning."
- Before collecting details: "I'll ask a few questions so the right lawyer calls you. Please don't include anything you'd rather tell a lawyer directly; a short outline is enough." This keeps sensitive detail out of the chat log.
- When someone asks a legal question: "That's a question for a lawyer, because the answer depends on your circumstances. Shall I book a call?" No general legal information, even when the bot could produce some.
- At booking: "You're booked with [lawyer's first name] on [date] at [time]. You'll get a confirmation email from our team."
- At handover during office hours: "You're now chatting with [first name], one of our team." The customer sees the change.
Before the rewrite, the firm's greeting was a cheerful "How can I help?" and roughly one conversation in seven included the customer asking whether they were talking to a lawyer. After it, that question almost disappeared from the transcripts, and the share of chats that ended with a booked call rose, because customers stopped trying to get free advice from a bot that couldn't give it and moved straight to booking. The disclosure did the scoping work the old greeting left undone.
Lines for firms that can't give advice through a bot
In advice sectors the "what it can't do" line carries real weight, because a chatbot answering the wrong question can look like regulated advice. Filled-in lines for the sectors this applies to most:
| Business | The limit to state | Where it sends people |
|---|---|---|
| Law firm | "I can't give legal advice about your situation." | A booked call with a lawyer |
| Financial planner | "I can't give financial advice or recommend investments." | A review meeting with a planner |
| Mortgage adviser | "I can't tell you how much you could borrow or whether you'd be approved." | An adviser appointment |
| Insurance broker | "I can't confirm what your policy covers." | A broker, by chat handover or phone |
| Bookkeeping firm | "I can't advise on your accounts or tax position." | Your bookkeeper, by email |
State the limit in the greeting and enforce it in the instructions, so the bot declines and redirects when the question arrives anyway. The companion tutorial on chatbot guardrails covers keeping the assistant from promising things beyond its limits.
Beyond the greeting: handovers, email, voice and WhatsApp
Disclosure isn't only an opening line. The same principle applies wherever customers might not know whether a person or software is responding:
- Handover to a person. Announce it: "You're now chatting with [first name], one of our team." And if a person hands back to the bot, say that too.
- Returning customers. Disclose at the start of every new conversation, not only on a first visit.
- Out of hours. Say when a person will actually see the message: "Our team is back at 9am on Monday and will reply then." Never "someone will be with you shortly" at 11pm on a Friday; it implies a person is standing by.
- Email. If an AI system sends replies without a person reviewing them, say so in the reply: "This reply was written by our automated assistant. Reply 'person' to reach our team."
- Voice. An AI receptionist should say what it is in its first sentence, before asking anything. Scripts for that are in call scripts and escalation rules for an AI receptionist.
- WhatsApp. WhatsApp's Business Messaging Policy allows automation within the 24-hour service window only if you also have "prompt, clear, and direct escalation paths", such as transfer to a human agent in the chat, a phone number, email or a support form. Put that route in the greeting.
AI replies switched on inside tools you already use
Not every AI assistant arrives as a chat widget someone chose to install. Several business tools now include AI that answers customers directly once it's enabled. Shopify Inbox, for example, includes a free AI agent that replies to customers on its own, and Meta's Business Agent can answer messages in WhatsApp, Instagram and Messenger on a business's behalf. The disclosure question applies to these as much as to a bot you built.
For each tool where AI may be replying to customers, check three things: what the customer sees in the first reply, whether you can edit that text to add a plain disclosure and a route to a person, and whether the AI's answers to your own policy questions are right. Shopify, for instance, notes its agent can use web search as a secondary source, which is a good reason to test it against your returns and delivery policies before customers do. If a tool gives you no way to disclose, put the disclosure in the channel's greeting or auto-reply instead, and ask the vendor what the customer is shown.
Proving the disclosure works
Four checks, the first before launch and the rest ongoing:
- A five-person test. Ask five people who haven't seen the assistant to use it for a realistic task, then ask one question: were you talking to a person or software? Anyone who says "a person" or "not sure" means the greeting needs work.
- A transcript search. Each week, search conversations for "real person", "human", "bot" and "are you". A handful is normal; a rising count means customers are confused.
- An accessibility check. Use a screen reader on the chat window. If the disclosure is only an icon or badge, a screen-reader user may never hear it; the words must be in the message text.
- A dated record. Keep a screenshot of the greeting and instructions each time you change them, with the date. If anyone ever asks how customers were informed on a particular day, you can show them.
None of this takes more than an hour to set up, and it removes a whole category of complaint: the customer who feels misled about who they were talking to. The disclosure is also the cheapest scoping tool you have, because every question the bot can't answer that a customer doesn't ask is a frustration avoided.
Chatbot disclosure: further questions
Do I need to disclose if a person reviews every AI reply before it's sent?
That setup is different from a chatbot talking directly to customers, because a person decides what goes out. Many businesses still mention it in their privacy notice or website AI statement for openness. If the AI starts sending anything without review, even out of hours, treat it as a chatbot and disclose at the start of the conversation.
Is a small 'AI' badge next to the chat window enough?
Rarely on its own. The disclosure should be clear, distinguishable and accessible at the first interaction, which a badge that screen readers skip or customers overlook may not be. Put the words in the first message itself, and keep the badge as a reminder. It costs one sentence and removes the doubt.
Do I have to repeat the disclosure in every conversation?
Repeat it at the start of each new conversation, not just the first ever visit. Customers return weeks later, other people in a household use the same device, and chat histories get forwarded. The greeting is where it belongs, so it repeats automatically without cluttering the rest of the conversation.
Further reads
- How to Test a Customer Chatbot Before It Goes Live — Test the whole bot, greeting included, before customers see it.
- Who Is Liable When Your AI Chatbot Gets It Wrong? — Who carries the risk when a disclosed chatbot still gets it wrong.
- How to Set Up a WhatsApp AI Chatbot for Your Business — Setting up an AI assistant on WhatsApp within its rules.
- Can Customers Tell When a Reply Was Written by AI? — What customers notice about AI replies, disclosed or not.
- How to Label AI-Generated Images and Video on Social Media — The other half of Article 50: labelling AI images and video.
- AI Literacy Requirements: What Your Staff Need to Know — The AI Act duty that applies to your staff, not your chatbot.
- A Simple AI Risk Register for Small Businesses (With Template) — A one-table AI risk register with a scoring scale, a template to copy, twelve filled-in rows from a florist and the triggers for updating it.
- Customer-Facing or Back-Office: Where Should AI Go First? — A side-by-side comparison of customer-facing and back-office AI as a first move, with a scoring sheet, the middle route, and two worked decisions.
- How to Build the FAQ Your AI Chatbot Needs Before Launch — How to source, write and test the FAQ a small business chatbot answers from, with a copyable entry format and a handover list.
- Should a Hair Salon Use an AI Receptionist? — A decision test for salon owners: count your missed calls, check your software, and set the colour and patch-test rules before any AI answers the phone.
- Can AI Answer Gym Enquiries and Book Trial Sessions? — What an AI assistant can safely answer for a gym, how it books a trial, and why it must collect a phone number before Instagram's 24-hour window closes.
- Can an AI Chatbot Handle Order Tracking and Returns? — What an order-tracking chatbot needs to see, which return decisions it can safely make, and where a person still has to step in.
- Online Shop AI Mistakes That Hurt Trust and Conversions — Eight AI mistakes that quietly raise returns and lower sales in small online shops, each with a real-looking example and the fix.
- Should Coaches Build an AI Version of Their Method for Clients? — When an AI version of a coaching method helps clients and when it undermines you, what to build it on now custom GPTs are retiring, and the guardrails it needs.
- AI Chatbots for Nursery Enquiries and Visit Bookings — What a nursery chatbot should answer, what it must hand to the manager, how show-round booking works, and the two mistakes that cost parents' trust.
- How Charities Use AI Chatbots to Answer Supporter Questions — Which supporter questions a charity chatbot should answer, which it must hand over, and how to test it on 50 real questions before launch.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act text, Articles 3, 50 and 99 (via the AI Act Explorer); WhatsApp Business Messaging Policy. Checked September 2026. This is practical guidance, not legal advice.