AI Security, Privacy and ComplianceCustomer Service Automation

Do You Have to Tell Customers They're Talking to an AI Chatbot, Not a Human?

Last updated 21 July 2026 · 11 min read

Direct Answer

Often, yes, and for an Australian business the obligation comes from more than one source. The Australian Consumer Law's prohibition on misleading or deceptive conduct, enforced by the ACCC, already treats a chatbot built or presented to pass as human as a potential deception risk — there's no single bright-line 'you must disclose AI chatbots' statute, but the same standard the ACCC applies to deceptive advertising and dark patterns generally extends naturally to an undisclosed AI chatbot. Separately, from 10 December 2026, amendments to the Privacy Act 1988 require APP entities to disclose in their privacy policy where personal information is used in automated decision-making that could significantly affect someone — a related but distinct transparency duty, and one the OAIC is actively developing further guidance on. If you also have customers or users in the EU, Article 50 of the EU AI Act separately requires telling people they're interacting with an AI system before or at the start of that interaction, applicable from 2 August 2026 — an additional, EU-specific layer, not the primary law an Australian business needs to satisfy. In practice: put a clear, upfront statement that the customer is talking to AI on any chat, voice, or automated written channel, check the rules for every jurisdiction you serve, and don't rely on a vague name alone to count as disclosure.

Detailed Explanation

The short answer, for an Australian business, is "often, yes," but the obligation doesn't come from one single law — it comes from at least three different sources, and mixing them up is the most common way businesses get the compliance question wrong.

The Australian Consumer Law's prohibition on misleading or deceptive conduct — enforced by the ACCC and applying to every Australian business regardless of size, location, or which AI vendor it uses — can treat a chatbot built to pass as a human, or used to mislead customers, as an unfair or deceptive practice, the same standard the ACCC applies to deceptive advertising and dark patterns generally. Separately, from 10 December 2026, Privacy Act amendments require APP entities to disclose in their privacy policy where personal information feeds into automated decision-making that could significantly affect someone — a related but distinct, privacy-policy-level transparency duty rather than a point-of-interaction disclosure rule. And if your business has customers or users in the EU, does the EU AI Act apply to a business using ChatGPT or Claude covers the Act's risk-tier structure in general; a customer-facing chatbot or AI voice system sits in the Act's "limited risk" tier, which carries a specific, standalone transparency obligation — Article 50 — regardless of which underlying model or vendor you use.

These sources don't always point to the same answer for a given business. A domestic Australian business with no EU customers isn't covered by Article 50 at all, but is still squarely within the ACL's deception principles and, if it uses AI in significant automated decisions, the Privacy Act's new transparency duty. An EU-facing business additionally has to satisfy Article 50 specifically, which is more prescriptive about when the disclosure has to appear than general deception law is. Treat this as "check what actually applies to where my customers are," not as one universal rule.

The EU AI Act's Disclosure Requirement

Article 50 of the EU AI Act requires that a person be informed they are interacting with an AI system — such as a chatbot or a conversational voice assistant — unless this is obvious from the circumstances to a reasonably observant person. Two details matter more than the headline rule:

  • Timing. The notice has to be given before or at the point the interaction begins, not buried later in the conversation or only available if the customer digs for it.
  • Where it doesn't apply. The "obvious from context" exception is a genuine exception, not a loophole — regulators have indicated it's judged against what a reasonably attentive person in the actual audience would understand, with a stricter standard where the audience is likely to include children, older people, or people with disabilities. A chat widget with a human-sounding name and a friendly avatar is not automatically "obvious."

These obligations become applicable from 2 August 2026 — confirm this date and any related guidance against the current official implementation timeline before relying on it, since several AI Act provisions have already been subject to phased and revised dates. As with the rest of the Act, this applies to your business as a "deployer" using the tool, not only to Anthropic, OpenAI, or whichever vendor built it — see does the EU AI Act apply to a business using ChatGPT or Claude for that distinction in full.

Australian Consumer Law and the New Privacy Act Transparency Duty

There is no single Australian statute requiring "tell customers they're talking to AI" the way Article 50 does. What exists instead is general consumer-protection and privacy law applied to AI specifically:

  • Australian Consumer Law, section 18. The ACCC has been clear that using AI tools to impersonate a human, or in ways designed to deceive consumers, can be misleading or deceptive conduct — the same standard the ACCC applies to deceptive advertising and dark patterns generally, extended naturally to generative AI and chatbots. There's no bright-line "you must disclose AI in exactly this way" federal rule, but a chatbot built or presented specifically to be mistaken for a human support agent is the kind of practice that sits squarely within the ACCC's enforcement focus, not a hypothetical risk.
  • The Privacy Act's automated decision-making transparency duty. From 10 December 2026, an APP entity's privacy policy must disclose the kinds of personal information used, and the kinds of decisions made, through automated decision-making that could significantly affect an individual's rights or interests. This is a privacy-policy disclosure obligation rather than a point-of-interaction "you're talking to AI" statement, but it pushes in the same direction — the OAIC has signalled it expects a broad reading of what counts as a "significant" automated decision, and final guidance is expected to develop through 2026.
  • A small number of overseas jurisdictions have their own standalone bot-disclosure statutes — California's B.O.T. Act is the best-known example, applying to public-facing platforms with at least 10 million monthly US visitors — but these only matter if your business actually serves customers there; they aren't the law that governs an Australian business's own chatbot by default.

The practical takeaway: even where no single Australian statute names "AI chatbot disclosure" directly, disclosing plainly costs little and removes the deception risk entirely — it's the safer default regardless of which specific rule technically applies to your size and location.

What to Disclose, by Channel

Chat widgets. Put an explicit statement early in the conversation — not only a persistent label in the header — along the lines of "You're chatting with an AI assistant." See how do you build a chatbot from your help docs for the rest of what a help-docs chatbot needs beyond disclosure, including the escalation rule that should sit right alongside it: a customer told they're talking to AI needs a clear, working way to reach a person.

Voice and IVR. Disclosure needs to be spoken, near the start of the call, not left to a recorded terms-and-conditions message the caller is unlikely to be listening for. See can AI automate phone support and IVR for a small business for how this fits into a wider voice-automation setup — voice carries a stricter practical bar than chat because a caller can't scroll back to re-check what they were told.

AI-assisted written communication. This is where the line matters most. A human employee using AI to draft an email, proposal, or reply that they then personally review and send under their own name is not the case this obligation targets — the AI is a drafting aid, not the thing interacting with the customer. It's a different situation if a system generates and sends written communication automatically, presented as coming from a specific named person ("your account manager, Sarah") when no such person was involved — that crosses into the same deception concern as an unlabelled chatbot, regardless of which specific statute would apply.

Practical Wording and Placement

A few patterns that satisfy the "clear, upfront, not buried" standard across sources:

  • Chat: A first message before any other exchange — "Hi, I'm an AI assistant. I can help with [X, Y, Z]. Say 'agent' any time to reach a person." — rather than relying on a header label alone.
  • Voice/IVR: A short spoken line at the very start of the call, before routing — "You're speaking with an automated assistant" — with a stated way to reach a person immediately.
  • What doesn't count: a disclosure only in a linked terms-of-service page, a generic "AI-powered" badge with no accompanying statement in the conversation itself, or a disclosure that only appears after several exchanges have already happened.

What Happens If You Skip It

Consequences differ by which rule applies, and all of the figures below are time-sensitive — verify current amounts and enforcement posture before treating any of them as settled:

  • Under the Australian Consumer Law, the ACCC can pursue enforcement action for misleading or deceptive conduct, with maximum penalties for corporations that have grown substantially in recent years — reaching whichever is greatest of a large fixed amount, three times the benefit gained, or a percentage of adjusted turnover — alongside the reputational cost of a public ACCC action against "deceiving customers with an undisclosed AI chatbot."
  • Under the Privacy Act's ADM transparency duty, the OAIC has infringement notice powers for a non-compliant privacy policy, with penalties reaching into the hundreds of thousands of dollars — a distinct exposure from the ACL, and one that applies even without a customer complaint if the privacy policy itself doesn't meet the new disclosure standard.
  • Under the EU AI Act, Article 50 non-compliance carries fines that can reach a meaningful percentage of global annual turnover or a fixed cap, whichever regime applies to the specific violation — but only relevant if your business actually has EU customers or users in scope.

Things to Consider

  • Disclosure and good chatbot design point the same direction. A clear "you're talking to AI, say 'agent' for a person" statement isn't just a compliance requirement — it also sets the right expectation for how much the system can actually do, which reduces frustration regardless of which law technically applies to your business.
  • This is separate from your internal AI usage policy. See what should an employee AI usage policy include for the rules governing what staff can do with AI tools internally — that policy and customer-facing disclosure address two different audiences and don't substitute for each other.
  • Multi-channel businesses need this checked per channel, not once for "our AI." A business running a help-docs chatbot, a voice IVR, and AI-assisted email replies has three separate disclosure surfaces to get right, and a disclosure statement that works for chat doesn't automatically transfer to a phone script.
  • This is a genuinely fast-moving area. The Privacy Act's ADM transparency guidance (still being finalised by the OAIC), ACCC enforcement priorities, and the EU AI Act's transparency provisions are all still changing as of mid-2026 — treat any specific figure or threshold in this page as needing a re-check against current sources before you rely on it for a real compliance decision, and get a lawyer's opinion for anything with real financial exposure.
  • "Obvious from context" is a narrow exception, not a way around this. Don't assume that because a chatbot's limitations are apparent to you as the business owner, they're equally apparent to every customer — the standard is what a reasonably attentive person in your actual audience would understand, not what's obvious to someone who already knows it's a bot.

Common Mistakes

  • Treating a bot's name or avatar as sufficient disclosure. A friendly name and a robot icon aren't the same as an explicit statement, and regulators have specifically called out ambiguous branding as inadequate.
  • Burying the disclosure in terms of service. A disclosure nobody reads before or during the interaction doesn't satisfy any of the standards covered here — it has to be perceivable in the interaction itself.
  • Assuming a domestic Australian business with no EU customers has nothing to worry about. The ACL's deception principles and the Privacy Act's new ADM transparency duty both apply regardless of the EU AI Act, and "we don't have EU customers" only rules out one of the three sources covered on this page.
  • Applying the same disclosure rule to AI-assisted drafting as to a fully automated chatbot. A human reviewing and sending AI-drafted correspondence under their own name is a materially different situation from an AI system autonomously messaging a customer — conflating the two either creates unnecessary disclosure noise or, worse, misses the case that actually needs it.
  • Treating this as a one-time setup task. Regulatory guidance in this area — particularly the EU AI Act's implementation details — is still developing; a disclosure approach that was compliant last year is worth re-checking, not assumed to still be current.

Frequently Asked Questions

Does labeling a chat widget 'Bot' or giving it a friendly name count as disclosure?
Not reliably. A name alone, without an explicit statement that the customer is talking to AI, is exactly the kind of ambiguous signal regulators have flagged as insufficient — the EU AI Act's 'obvious from context' carve-out is judged against a reasonably observant person, not an ideal one, and a branded persona like 'Ava' can easily read as a human agent's name. Use an explicit first-message statement rather than relying on naming alone.
Do you have to disclose it if a human employee used AI to help draft a message before sending it themselves?
Generally no, for the EU AI Act's chatbot-specific transparency rule — that obligation targets AI systems that interact directly with people, not AI used as a drafting aid by a human who reviews and sends the message under their own identity. The separate deception principle still applies, though: if the content itself is misleading (fabricated claims, a fake personal anecdote), using AI to draft it doesn't create new liability, but it doesn't remove existing liability either.
Does this obligation cover internal tools, like an AI assistant employees use to look up policy answers?
No — this page is about disclosure to external customers and users. An internal-only AI tool that no customer ever interacts with directly isn't in scope of the customer-facing transparency rules covered here; it falls instead under a business's own employee AI usage policy.
Does the EU AI Act apply if my business is based in Australia?
Only if your business has customers or users in the EU — the Act's transparency obligation is triggered by where the interaction reaches people, not where the business is headquartered, so an Australian business with EU customers or users can still be in scope. An Australian business with no EU-facing presence doesn't need to satisfy Article 50 specifically, but should still work through the Australian Consumer Law and Privacy Act obligations covered on this page, which apply regardless of EU exposure.

References

Related Questions