# AI chatbot privacy policy and disclosure requirements

> AI chatbots must tell users they are talking to AI under model-provider policies and EU AI Act Article 50, and disclose where conversation data goes.

A customer-facing AI chatbot or assistant has two disclosure jobs. It must tell people they are interacting with AI rather than a human, which model providers such as Anthropic require and which EU AI Act Article 50 requires from 2 August 2026. Its privacy policy must also explain where conversation data goes: the model provider, storage and retention, training use, human review, and any automated decisions.

Canonical URL: https://legalpolicygenerator.com/resources/ai-chatbot-privacy-policy

## Model-provider usage policies

Anthropic's Usage Policy, effective 15 September 2025, states that all consumer-facing chatbots, including any external-facing or interactive AI agent, must disclose to users that they are interacting with AI rather than a human. For certain high-risk use cases where outputs are presented directly to consumers, it also requires disclosure that AI is being used at the start of each session. Other model providers publish their own usage policies with disclosure and transparency expectations; read the current version for the provider you use, because it becomes part of your contract.

## EU AI Act Article 50 transparency

Article 50 of Regulation (EU) 2024/1689, the AI Act, applies from 2 August 2026. Article 50(1) requires providers to design AI systems intended to interact directly with natural persons so that the people concerned are informed that they are interacting with an AI system, unless this is obvious from the circumstances. Article 50(3) requires deployers of emotion recognition or biometric categorisation systems to inform the people exposed, and Article 50(4) requires deployers to disclose deep fakes and certain AI-generated or manipulated content. A later amending regulation adjusted transition timing for some marking obligations for systems already on the market; check the current consolidated text.

## App Store rules for third-party AI

Apple guideline 5.1.2(i) requires apps to clearly disclose where personal data will be shared with third parties, including with third-party AI, and to obtain explicit permission before doing so. An iOS app with a chatbot powered by an external model provider should name the provider in the privacy policy and ask for permission in the app before sending the first message.

## Where to place the AI disclosure

The notice that users are talking to AI belongs in the chat interface itself, for example in the chat header, the first message, or next to the input field, not only in the privacy policy. The privacy policy then explains the data handling behind it. If the assistant can hand over to human agents, say when that happens and whether the human sees the prior AI conversation.

## What the privacy policy should cover

Describe what is collected in conversations, including messages, uploaded files, and metadata such as account ID, page context, and device information; which model provider processes them and where; whether transcripts are stored and for how long; whether conversations are used to train or improve your models or the provider's; whether staff review conversations for quality or safety; and how users can delete conversations or opt out. The AI product disclosures guide covers these data flows in detail.

## Sensitive information and children

People share health, financial, and personal details with chatbots even when asked not to. Tell users what to avoid sharing and what happens if they do. If minors may use the chatbot, check COPPA and platform family rules and provider age requirements, which may restrict or prohibit use by children.

## Automated decisions

If the chatbot does more than answer questions, for example approving refunds, qualifying leads for credit, or screening job applicants, it may be making decisions with significant effects. GDPR Article 22 and several US state laws give people rights in that situation, and the policy must describe the logic involved and how to obtain human review.

## Generating a chatbot privacy policy

Choose the AI use case in the questionnaire, describe the AI features and the information sent to each named model provider, and confirm whether people interact with the AI, prompt storage and retention, training use, human review, permission before sharing personal data with a third-party AI provider, significant automated decisions, and the opt-out route. The generated AI section describes those facts, and the regional modules add GDPR, California, or other rights as selected. Add the in-product AI disclosure separately, because it is a user-interface requirement rather than policy text.

## Common questions

### Is a line in the privacy policy enough to disclose the chatbot is AI?

Usually not. Provider usage policies and Article 50 aim at people knowing at the point of interaction, so the disclosure should appear in the chat interface.

### Does Article 50 apply to companies outside the EU?

The AI Act can apply to providers and deployers outside the EU when their systems are placed on the EU market or their output is used in the EU. Check how your product reaches EU users.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
