The EU AI Act and Your Chat Data
A Plain-English Guide

Published July 24, 2026 · Updated August 18, 2026

This article is general information, not legal advice. The AI Act is being amended and clarified as it phases in; for your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.

The EU AI Act is not a privacy law, and it gives you very little say over your chat data — retention, training and lawful processing remain the GDPR's job, though the Act does add a right to complain to a market surveillance authority (Article 85) and a narrow right to an explanation for certain high-risk decisions (Article 86). What it does regulate is the AI systems themselves, and its most user-visible rules have applied since August 2, 2026: chatbots must tell you that you are talking to a machine unless that is already obvious, AI-generated content must carry a machine-readable mark where technically feasible, and deepfakes must be disclosed, on pain of fines up to €15 million or 3% of worldwide turnover. Meanwhile the "Digital Omnibus" amendment — Regulation (EU) 2026/1744, in force since July 27, 2026 — quietly postponed the Act's high-risk rules to late 2027 and 2028 — but deliberately left those transparency duties on schedule. Here is what the Act actually changes when you prompt a chatbot, what was already banned, what the model behind your chat must now publicly disclose, and where the Act stops and the GDPR takes over.

What the AI Act Is — and What It Isn't

The AI Act (Regulation (EU) 2024/1689, in force since August 1, 2024) is product regulation, built the way the EU regulates machinery or medical devices: it sorts AI systems into risk tiers and attaches duties to the companies that build and deploy them. A few practices are banned outright; "high-risk" uses (hiring, credit, policing and the like) get strict conformity requirements; everyday systems like chatbots mostly get transparency duties; and the general-purpose models underneath them get their own chapter of documentation and disclosure rules.

What the Act is not is a charter of individual rights over your data. It does not decide whether a provider may store your conversations, train on them, or how long it may keep them — all of that stays governed by the GDPR, which is why the two laws are best read as a stack: the AI Act disciplines the system, the GDPR disciplines the data. We covered the data side — including what "erasure" can and cannot reach inside a trained model — in our guide to the GDPR right to erasure.

The Timeline, Minus the Legalese

The Act phases in from 2024 to 2028, and the Digital Omnibus — Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July and in force from 27 July — reshuffled the back half of the schedule:

  • February 2, 2025 — the bans. The "unacceptable risk" practices became illegal, along with a duty for organizations to ensure basic AI literacy in their staff.
  • August 2, 2025 — rules for the models. Obligations for providers of general-purpose AI (GPAI) models — the GPT, Claude, Gemini and Grok class — took effect, together with the governance structure and the national penalty framework. One thing did not start then: the Commission's own power to fine GPAI providers only became applicable on 2 August 2026. Models already on the market before that date have until August 2, 2027 to comply.
  • August 2, 2026 — the user-facing layer. The Article 50 transparency obligations (chatbot disclosure, content marking, deepfake labels) apply, and the EU's AI Office gains its enforcement powers over model providers.
  • Postponed by the Digital Omnibus: the high-risk system obligations, originally also due August 2026, were deferred — to December 2, 2027 for stand-alone high-risk uses (Annex III) and August 2, 2028 for AI embedded in regulated products. The Omnibus was politically agreed in May 2026, adopted on July 8, 2026 and published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744; it entered into force on July 27, 2026 — deliberately on the third day after publication, so the amended deadlines were law before the Act's August 2 milestone. Crucially, it did not postpone the chatbot transparency rules — with one narrow exception we'll flag below.

What Changed on August 2, 2026

Article 50 is the part of the Act you actually notice, and it has applied since 2 August 2026. Four duties matter for chat users — each with real limits, which the summaries usually leave out:

  • You must be told you're talking to AI. This binds the provider of a system intended to interact directly with people — chatbots, voice agents, avatars — which must be designed so users are informed they are dealing with a machine, at the latest at the first interaction, unless it is already obvious to a reasonably well-informed person. The era of the customer-service "agent" that never admits it's a bot is legally over in the EU.
  • AI-generated content must carry a machine-readable mark. Providers of systems that generate text, images, audio or video must mark outputs as artificially generated in a machine-readable way (Article 50(2)). This is the one place the Omnibus granted breathing room: systems already on the market before August 2, 2026 get until December 2, 2026 for the marking duty, and content generated before August 2026 never needs retroactive labels. Note the duty is qualified rather than absolute — the Act asks for solutions that are effective and robust "as far as this is technically feasible", weighing the state of the art, the type of content and the cost of implementation, and the Commission's guidance carves out cases such as source code and ordinary assistive editing. Fair warning from practice: watermarking technology is still immature, so expect this piece to be the bumpiest.
  • Deepfakes must be disclosed. Anyone deploying AI-generated or manipulated images, audio or video that resembles real people, places or events must disclose the artificial origin.
  • AI-written text published to inform the public must be labeled. Whoever publishes AI-generated or AI-manipulated text on matters of public interest must say so visibly — unless a human reviewed it and someone holds editorial responsibility for the publication (Article 50(4)). This is the clause that reaches newsrooms and content sites, not just deepfake studios.
  • Emotion recognition and biometric categorization must be disclosed to the people exposed to them.

Four qualifications keep those duties from meaning quite what a headline suggests, and they are worth holding on to before you expect a label on everything:

  • Obviousness. The chatbot disclosure does not apply where it would be obvious to a reasonably well-informed person that they are dealing with AI.
  • Who is bound. Interaction disclosure is principally a provider duty; deepfake, public-interest text and emotion-recognition notices fall on the deployer. A person using AI in a purely personal, non-professional capacity is outside the deepfake duty altogether.
  • What counts as generated. The Article 50(2) marking duty is bounded by technical feasibility and does not bite where a system merely assists in editing without substantially altering the input or its meaning. Artistic, creative, satirical and fictional works get a lighter disclosure regime, and there are law-enforcement exceptions across these paragraphs.
  • The text exception is narrower than "a human looked at it". AI-written text on matters of public interest escapes labelling only where it underwent substantive human review or editorial control and a natural or legal person holds editorial responsibility for publication.

Breaching these transparency duties can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher — enforced by national market surveillance authorities. For SMEs and start-ups the Act flips that formula: Article 99(6) caps their fines at whichever of the two is lower, and penalties must in any case be proportionate. And any person can lodge a complaint with those authorities, which is the Act's main (modest) individual remedy.

What Was Already Banned

Since February 2025, a short list of AI practices is simply prohibited in the EU, with the Act's heaviest fines (up to €35 million or 7% of worldwide turnover). The ones closest to chat:

  • Manipulative or deceptive techniques that materially distort behavior and cause significant harm — including exploiting vulnerabilities of age, disability or social situation. A chatbot engineered to covertly steer vulnerable users into harmful decisions is not a compliance problem; it is an illegal product.
  • Emotion recognition at work and in schools (outside medical and safety uses).
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases, social scoring, and predictive policing based on profiling alone.
  • New with the Digital Omnibus — but not yet in effect: the amendment adds to Article 5 an explicit ban on AI systems that generate or manipulate non-consensual intimate imagery ("nudifier" apps) and child sexual abuse material. Unlike the bans above, this one applies from December 2, 2026, and it reaches providers whose systems produce such output as a reasonably foreseeable outcome — not only those who set out to build it — where that output can be reproduced without significant technical modification and the system lacks reasonable and adequate safeguards. Deployers are caught only where they use a system for that purpose. Effective technical safeguards against those outputs are the way out.

The Model Behind Your Chatbot Now Has Homework

The layer most users never see — the general-purpose model answering your prompts — has had its own obligations since August 2025, and two of them are genuinely useful to you:

  • A public summary of training content. Every GPAI provider placing a model on the EU market must publish, using the AI Office's mandatory template (published July 24, 2025) — models already on the market before 2 August 2025 have until 2 August 2027 — a summary of what its model was trained on: the major public datasets, licensed and scraped sources, and — notably — whether user data collected through people's interactions with the provider's own products and services went into training. Read it for what it is: a standard, comparable document telling you whether chats like yours are training material at all — not a record of whether one particular conversation of yours entered a model, which no summary will ever tell you. Even at that resolution it beats what we had before, which was decoding privacy policies, as in our 13-provider retention audit.
  • A copyright policy and technical documentation, with stricter risk-management duties for the largest "systemic risk" models.

Compliance is smoothed by the voluntary GPAI Code of Practice (July 2025): signing it does not confer a statutory presumption of conformity, despite how it is often described: the Act provides that adherence is taken into account in demonstrating compliance and reduces the administrative burden. Most major labs signed; Meta conspicuously declined. From August 2, 2026 the AI Office can verify compliance and order corrective measures — so expect these public summaries to get real scrutiny from now on.

What the AI Act Does Not Do for Your Chat Data

This is the part marketing copy tends to blur, so let's be precise. The AI Act does not:

  • Give you access, erasure or portability rights over your chats. Those exist only under the GDPR, come with its conditions and exceptions, and — as we've written — reach stored chats far better than trained models.
  • Stop providers from training on your conversations. Whether your chats may be used for training is a GDPR legal-basis question plus, practically, a settings question — the switches are in our platform-by-platform opt-out guide.
  • Limit how long your chats are retained, or make "temporary" modes genuinely temporary — the fine print we dissected in "Temporary Chat" Isn't What You Think is untouched by the Act.
  • Make you anonymous. Nothing in the Act stops a chatbot from tying every prompt to your account, profiling you across sessions, or logging the identifiers we cataloged in our fingerprinting article.

There is a narrow "right to explanation" in the Act, but it covers decisions made about you by high-risk systems (credit, hiring and the like) — not conversational AI, and its arrival now follows the postponed high-risk timeline.

One Prompt, Two Laws

Put the stack together and a single chat session in the EU now looks like this. Before you type, the AI Act requires that you know you're talking to a machine, and bans the system from manipulating you covertly. The moment you hit send, the GDPR takes over — insofar as what you typed, or the metadata around it, is personal data: whoever decides why and how it is processed (the controller, which is not automatically the same company the AI Act calls the provider) needs a lawful basis for it, and your rights of access, erasure, restriction and objection apply subject to the GDPR's own conditions and exceptions. Those rights are real but qualified: where training runs on legitimate interests you can object under Article 21 on grounds relating to your situation, and the controller must stop unless it demonstrates compelling legitimate grounds that override yours; where it runs on your consent, the lever is withdrawing that consent instead. When the answer comes back, the AI Act returns: generated content must be machine-readably marked, and a synthetic face or voice must be labeled. The system is disciplined; the data is disciplined; but linking the two — who said what to which model — is exactly the layer neither law removes. Whoever holds your chat logs still holds them.

Practical Takeaways

  • As a user, the Act costs you nothing and quietly improves your position: since August 2026 you can expect explicit "you are talking to AI" notices, labeled deepfakes, and public training-content summaries worth skimming before you trust a provider with sensitive chats. Your actual data rights still run through the GDPR — use them, and use the training opt-outs.
  • If you run a chatbot for EU users — even a small business widget — the transparency duties bind you, not just Big Tech: disclose the bot clearly, label AI-generated media, label AI-written text you publish to inform the public unless a human editor stands behind it, and mind the AI-literacy duty for staff. Fines are capped more gently for SMEs and start-ups, but the duties themselves apply to everyone from day one.
  • Don't mistake either law for content protection. Neither the AI Act nor the GDPR redacts what you type. If a prompt contains secrets, the only reliable filter is you, before sending.

How Secret Chat AI Fits — and Its Honest Limits

Secret Chat AI sits in the one gap the new rulebook leaves open: the link between you and your words. The AI Act will tell you a bot is a bot; it will not stop a provider from building a profile of you from your chats. Secret Chat's design does: it creates no profile of you, associates no chat with your identity, and passes your queries to the top models anonymously — your email is used only for account access and payment, never linked to your prompts, and your queries are never used for training. Your conversation history lives only in your own browser, not on our servers: a prompt exists on our side only for as long as it takes to fetch your answer, and there is no stored chat archive on our servers for any law to argue over.

And the honest limit, stated plainly as always: Secret Chat AI removes you from your queries — it does not remove the data from your messages. "Anonymously" here describes the link, not the words: no account identifier travels with your prompt. It is not a claim that the text itself stops being personal data — if you type your own name into a message, the message still contains your name, and under the GDPR's demanding test that is not anonymous. What you type reaches the model provider verbatim (anonymously, but verbatim) and is processed under that provider's terms, within the same AI Act and GDPR framework described above. Redacting names, secrets and identifying details before you send remains your responsibility, with us as with anyone.

Frequently Asked Questions

  1. Does the EU AI Act protect the privacy of my chats?

    Not directly. The AI Act regulates AI systems — transparency, banned practices, model documentation — not personal data. Storage, training use, retention and deletion of your chats remain governed by the GDPR. The two laws apply side by side.

  2. What changed for chatbot users on August 2, 2026?

    Since that date, systems designed to interact with people must inform you that you are dealing with AI — unless it is already obvious to a reasonably well-informed person — AI-generated content must carry a machine-readable mark as far as technically feasible, deepfakes must be disclosed (with a lighter regime for artistic, satirical and fictional work, and personal non-professional use outside scope), and AI-written text published to inform the public must be disclosed unless it had substantive human review or editorial control and someone holds editorial responsibility. Systems already on the market before 2 August 2026 have until 2 December 2026 for the marking duty. Violations risk fines up to €15 million or 3% of worldwide turnover — whichever is lower for SMEs and start-ups.

  3. Was the AI Act delayed?

    Partly. The Digital Omnibus amendment — Regulation (EU) 2026/1744, published on July 24, 2026 and in force since July 27, 2026 — postponed the high-risk system obligations to December 2027 (stand-alone uses) and August 2028 (AI in regulated products), and gave pre-existing systems until December 2, 2026 for machine-readable content marking. The chatbot disclosure and deepfake labeling duties were not delayed. It also added a new prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, applying from December 2, 2026.

  4. Does the AI Act stop providers from training on my conversations?

    No. Training on user chats is a GDPR question plus a settings question — most consumer platforms train by default and offer an opt-out. The Act does force model providers to publish a summary of their training content, which reveals whether user data is used at all.

  5. What is the public training-content summary?

    Since August 2025, every general-purpose AI model provider must publish a summary of its training data using the European Commission's mandatory template — covering major datasets, scraped and licensed sources, and whether the provider's own user data was included. Models marketed before August 2025 must comply by August 2, 2027.

  6. Does the AI Act make my chats anonymous?

    No law does. The Act mandates transparency about the system, not unlinkability of your data — a provider may still tie every prompt to your account. Anonymity is an architecture choice: Secret Chat AI keeps no server-side chat history and sends queries to the models with no identity attached, though the content you type still reaches the provider verbatim.

Conclusion

The AI Act's user-facing moment arrived on August 2, 2026, and it is worth welcoming for what it is: honest labels on machines and their output, a ban on the ugliest manipulative uses, and a first-ever public accounting of what the big models were trained on. It is equally worth seeing for what it is not: it grants you no new power over your chat data, no limit on retention, no shield from profiling, and no anonymity. Those still come from the GDPR where the law can reach — and from your own choices where it cannot: send less, opt out of training, and prefer services built so that your conversations are never linked to you in the first place.

Sources