The EU AI Act and Your Chat Data
A Plain-English Guide

Published July 24, 2026

This article is general information, not legal advice. The AI Act is being amended and clarified as it phases in; for your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.

The EU AI Act is not a privacy law, and it gives you almost no rights over your chat data — that remains the GDPR's job. What it does regulate is the AI systems themselves, and its most user-visible rules arrive on August 2, 2026: every chatbot serving EU users must tell you that you are talking to a machine, AI-generated content must carry a machine-readable mark, and deepfakes must be labeled, on pain of fines up to €15 million or 3% of worldwide turnover. Meanwhile the "Digital Omnibus" amendment, signed in July 2026, quietly postponed the Act's high-risk rules to late 2027 and 2028 — but deliberately left those transparency duties on schedule. Here is what the Act actually changes when you prompt a chatbot, what was already banned, what the model behind your chat must now publicly disclose, and where the Act stops and the GDPR takes over.

What the AI Act Is — and What It Isn't

The AI Act (Regulation (EU) 2024/1689, in force since August 1, 2024) is product regulation, built the way the EU regulates machinery or medical devices: it sorts AI systems into risk tiers and attaches duties to the companies that build and deploy them. A few practices are banned outright; "high-risk" uses (hiring, credit, policing and the like) get strict conformity requirements; everyday systems like chatbots mostly get transparency duties; and the general-purpose models underneath them get their own chapter of documentation and disclosure rules.

What the Act is not is a charter of individual rights over your data. It does not decide whether a provider may store your conversations, train on them, or how long it may keep them — all of that stays governed by the GDPR, which is why the two laws are best read as a stack: the AI Act disciplines the system, the GDPR disciplines the data. We covered the data side — including what "erasure" can and cannot reach inside a trained model — in our guide to the GDPR right to erasure.

The Timeline, Minus the Legalese

The Act phases in over four years, and a 2026 amendment reshuffled the back half of the schedule:

  • February 2, 2025 — the bans. The "unacceptable risk" practices became illegal, along with a duty for organizations to ensure basic AI literacy in their staff.
  • August 2, 2025 — rules for the models. Obligations for providers of general-purpose AI (GPAI) models — the GPT, Claude, Gemini and Grok class — took effect, together with the governance structure and penalty regime. Models already on the market before that date have until August 2, 2027 to comply.
  • August 2, 2026 — the user-facing layer. The Article 50 transparency obligations (chatbot disclosure, content marking, deepfake labels) apply, and the EU's AI Office gains its enforcement powers over model providers.
  • Postponed by the Digital Omnibus: the high-risk system obligations, originally also due August 2026, were deferred — to December 2, 2027 for stand-alone high-risk uses (Annex III) and August 2, 2028 for AI embedded in regulated products. The Omnibus was politically agreed in May 2026 and signed on July 8, 2026; at the time of writing it awaits publication in the EU's Official Journal. Crucially, it did not postpone the chatbot transparency rules — with one narrow exception we'll flag below.

What Changes for You on August 2, 2026

Article 50 is the part of the Act you will actually notice, and it lands in days. Four duties matter for chat users:

  • You must be told you're talking to AI. Any AI system that interacts directly with people — chatbots, voice agents, avatars — must be designed so users are informed they are dealing with a machine, at the latest at the first interaction, unless it is already obvious to a reasonably well-informed person. The era of the customer-service "agent" that never admits it's a bot is legally over in the EU.
  • AI-generated content must carry a machine-readable mark. Providers of systems that generate text, images, audio or video must mark outputs as artificially generated in a machine-readable way (Article 50(2)). This is the one place the Omnibus granted breathing room: systems already on the market before August 2, 2026 get until December 2, 2026 for the marking duty, and content generated before August 2026 never needs retroactive labels. Fair warning from practice: watermarking technology is still immature, so expect this piece to be the bumpiest.
  • Deepfakes must be disclosed. Anyone deploying AI-generated or manipulated images, audio or video that resembles real people, places or events must disclose the artificial origin.
  • Emotion recognition and biometric categorization must be disclosed to the people exposed to them.

Breaching these transparency duties can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher — enforced by national market surveillance authorities. And any person can lodge a complaint with those authorities, which is the Act's main (modest) individual remedy.

What Was Already Banned

Since February 2025, a short list of AI practices is simply prohibited in the EU, with the Act's heaviest fines (up to €35 million or 7% of worldwide turnover). The ones closest to chat:

  • Manipulative or deceptive techniques that materially distort behavior and cause significant harm — including exploiting vulnerabilities of age, disability or social situation. A chatbot engineered to covertly steer vulnerable users into harmful decisions is not a compliance problem; it is an illegal product.
  • Emotion recognition at work and in schools (outside medical and safety uses).
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases, social scoring, and predictive policing based on profiling alone.
  • New with the Digital Omnibus: the amendment adds an explicit ban on AI systems for generating non-consensual intimate imagery ("nudifier" apps) and child sexual abuse material.

The Model Behind Your Chatbot Now Has Homework

The layer most users never see — the general-purpose model answering your prompts — has had its own obligations since August 2025, and two of them are genuinely useful to you:

  • A public summary of training content. Every GPAI provider must publish, using the AI Office's mandatory template (published July 24, 2025 — a year ago today), a summary of what its model was trained on: the major public datasets, licensed and scraped sources, and — notably — whether user data collected from the provider's own services went into training. For the first time there is a standard, comparable document answering "did my chats feed this model?" — a question we previously could only answer by decoding privacy policies, as in our 13-provider retention audit.
  • A copyright policy and technical documentation, with stricter risk-management duties for the largest "systemic risk" models.

Compliance is smoothed by the voluntary GPAI Code of Practice (July 2025): signing it earns providers a presumption of conformity. Most major labs signed; Meta conspicuously declined. From August 2, 2026 the AI Office can verify compliance and order corrective measures — so expect these public summaries to get real scrutiny from now on.

What the AI Act Does Not Do for Your Chat Data

This is the part marketing copy tends to blur, so let's be precise. The AI Act does not:

  • Give you access, erasure or portability rights over your chats. Those exist only under the GDPR — and, as we've written, they reach stored chats far better than trained models.
  • Stop providers from training on your conversations. Whether your chats may be used for training is a GDPR legal-basis question plus, practically, a settings question — the switches are in our platform-by-platform opt-out guide.
  • Limit how long your chats are retained, or make "temporary" modes genuinely temporary — the fine print we dissected in "Temporary Chat" Isn't What You Think is untouched by the Act.
  • Make you anonymous. Nothing in the Act stops a chatbot from tying every prompt to your account, profiling you across sessions, or logging the identifiers we cataloged in our fingerprinting article.

There is a narrow "right to explanation" in the Act, but it covers decisions made about you by high-risk systems (credit, hiring and the like) — not conversational AI, and its arrival now follows the postponed high-risk timeline.

One Prompt, Two Laws

Put the stack together and a single chat session in the EU now looks like this. Before you type, the AI Act requires that you know you're talking to a machine, and bans the system from manipulating you covertly. The moment you hit send, the GDPR takes over: the provider needs a legal basis to process and store your words, must honor access and erasure requests over the stored copies, and must let you object to training. When the answer comes back, the AI Act returns: generated content must be machine-readably marked, and a synthetic face or voice must be labeled. The system is disciplined; the data is disciplined; but linking the two — who said what to which model — is exactly the layer neither law removes. Whoever holds your chat logs still holds them.

Practical Takeaways

  • As a user, the Act costs you nothing and quietly improves your position: from August 2026 you can expect explicit "you are talking to AI" notices, labeled deepfakes, and public training-content summaries worth skimming before you trust a provider with sensitive chats. Your actual data rights still run through the GDPR — use them, and use the training opt-outs.
  • If you run a chatbot for EU users — even a small business widget — the transparency duties bind you, not just Big Tech: disclose the bot clearly, label AI-generated media, and mind the AI-literacy duty for staff. The fines scale to turnover, but they start applying to everyone.
  • Don't mistake either law for content protection. Neither the AI Act nor the GDPR redacts what you type. If a prompt contains secrets, the only reliable filter is you, before sending.

How Secret Chat AI Fits — and Its Honest Limits

Secret Chat AI sits in the one gap the new rulebook leaves open: the link between you and your words. The AI Act will tell you a bot is a bot; it will not stop a provider from building a profile of you from your chats. Secret Chat's design does: it creates no profile of you, associates no chat with your identity, and passes your queries to the top models anonymously — your email is used only for account access and payment, never linked to your prompts, and your queries are never used for training. Your conversation history lives only in your own browser, not on our servers, so there is no server-side chat log on our side for any law to argue over.

And the honest limit, stated plainly as always: Secret Chat AI removes you from your queries — it does not remove the data from your messages. What you type reaches the model provider verbatim (anonymously, but verbatim) and is processed under that provider's terms, within the same AI Act and GDPR framework described above. Redacting names, secrets and identifying details before you send remains your responsibility, with us as with anyone.

Frequently Asked Questions

  1. Does the EU AI Act protect the privacy of my chats?

    Not directly. The AI Act regulates AI systems — transparency, banned practices, model documentation — not personal data. Storage, training use, retention and deletion of your chats remain governed by the GDPR. The two laws apply side by side.

  2. What changes for chatbot users on August 2, 2026?

    Chatbots serving EU users must clearly inform you that you are interacting with AI, AI-generated content must carry a machine-readable mark, and deepfakes must be labeled. Violations risk fines up to €15 million or 3% of worldwide turnover.

  3. Was the AI Act delayed?

    Partly. The Digital Omnibus amendment, signed in July 2026, postponed the high-risk system obligations to December 2027 (stand-alone uses) and August 2028 (AI in regulated products), and gave pre-existing systems until December 2, 2026 for machine-readable content marking. The chatbot disclosure and deepfake labeling duties were not delayed.

  4. Does the AI Act stop providers from training on my conversations?

    No. Training on user chats is a GDPR question plus a settings question — most consumer platforms train by default and offer an opt-out. The Act does force model providers to publish a summary of their training content, which reveals whether user data is used at all.

  5. What is the public training-content summary?

    Since August 2025, every general-purpose AI model provider must publish a summary of its training data using the European Commission's mandatory template — covering major datasets, scraped and licensed sources, and whether the provider's own user data was included. Models marketed before August 2025 must comply by August 2, 2027.

  6. Does the AI Act make my chats anonymous?

    No law does. The Act mandates transparency about the system, not unlinkability of your data — a provider may still tie every prompt to your account. Anonymity is an architecture choice: Secret Chat AI keeps no server-side chat history and sends queries to the models with no identity attached, though the content you type still reaches the provider verbatim.

Conclusion

The AI Act's user-facing moment arrives on August 2, 2026, and it is worth welcoming for what it is: honest labels on machines and their output, a ban on the ugliest manipulative uses, and a first-ever public accounting of what the big models were trained on. It is equally worth seeing for what it is not: it grants you no new power over your chat data, no limit on retention, no shield from profiling, and no anonymity. Those still come from the GDPR where the law can reach — and from your own choices where it cannot: send less, opt out of training, and prefer services built so that your conversations are never linked to you in the first place.

Sources