The Chatbot Confesses. The Algorithm Decides.

Imagine the scene.

You apply for a job. A chatbot welcomes you to the company’s website. From 2 August 2026, it will have to inform you that you are interacting with an artificial intelligence system, unless this is already obvious to a reasonably informed and attentive person.

You continue the conversation. You describe your experience, skills, salary expectations and availability.

Then you upload your résumé.

At that moment, the visible AI disappears behind the screen.

Another system analyses your career history, compares your experience with previous applicants, assigns scores, ranks your profile and may recommend whether you should be interviewed or rejected.

This second AI has no face. It does not speak. It may not visibly introduce itself. Yet its influence on your life can be far greater than that of the chatbot that has just welcomed you.

Europe has adopted a timetable that captures this paradox perfectly: the AI that talks to you will have to identify itself from 2 August 2026, while the AI that may influence your professional future receives another sixteen months to reach full compliance with the specific high-risk rules.

Visible AI will need to show its badge

Article 50 of the AI Act establishes transparency obligations for several categories of systems.

Providers of systems designed to interact directly with people must inform them that they are communicating with an AI system, unless this is already clear from the circumstances.

The same article provides for machine-readable marking of certain AI-generated or manipulated content. Deepfakes and some artificial publications concerning matters of public interest must also be disclosed under the conditions set out in the regulation.

These transparency obligations are scheduled to apply from 2 August 2026. (European Commission)

The intention is understandable.

A person should know whether they are talking to a human being, an automated system or an artificial agent capable of imitating a human interlocutor.

This transparency addresses one initial form of manipulation: presenting a machine as a person.

For companies, compliance involves far more than adding a sentence beneath a chat window. They must identify the interfaces concerned, determine who legally provides or deploys them, validate the wording of the disclosure and document the measures implemented.

A chatbot operated by marketing, customer service, human resources or technical support therefore becomes a governance issue.

The AI screening résumés follows another timetable

The AI Act classifies certain uses of artificial intelligence as high-risk.

This category covers systems used in areas including critical infrastructure, education, employment, access to essential services, migration, justice and law enforcement.

In employment, the scope includes tools used to place targeted job advertisements, analyse or filter applications, evaluate candidates, monitor performance, allocate tasks or influence decisions concerning promotion and termination.

On 29 June 2026, the Council of the European Union gave its final approval to an amending regulation establishing new application dates.

Requirements for stand-alone high-risk systems covered by Annex III are now scheduled to apply by 2 December 2027. The corresponding date for high-risk systems embedded in certain regulated products is 2 August 2028. (Council of the European Union)

There are sixteen months between 2 August 2026 and 2 December 2027.

During that period, a chatbot will have to disclose its artificial nature, while some of the specific compliance duties governing a recruitment algorithm will remain deferred.

This contrast deserves the attention of corporate leaders.

The most visible AI is rarely the one carrying the greatest risk.

A polite interface can conceal an opaque decision

A chatbot can waste a few minutes of your time.

A poorly designed recruitment system can cost you a professional opportunity.

A conversational assistant can produce an awkward answer.

A credit-scoring algorithm can influence access to housing, financing or an entrepreneurial project.

An educational tool can recommend a learning pathway.

A workplace monitoring system can evaluate an employee, interpret behaviour or report an alleged decline in performance.

Risk therefore depends on more than an AI system’s ability to produce convincing text, images or conversations. It depends primarily on the authority an organisation gives to its outputs.

The same technology can be almost harmless in one context and critical in another.

An AI recommending a film does not have the same impact as an AI recommending a dismissal.

An AI helping someone rewrite a résumé does not have the same impact as an AI ranking that résumé below an invisible threshold.

An AI helping a recruiter draft an advertisement does not perform the same function as an AI automatically excluding candidates.

Risk mapping must therefore begin with use cases and consequences, rather than software brands or the apparent sophistication of a model.

Why did Europe grant the delay?

The postponement is partly connected to delays in producing harmonised standards, guidance and implementation tools.

The European Commission asked European standardisation organisations to translate legal requirements into common technical frameworks.

Their work covers risk management, data governance, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment.

These standards can give companies a clearer path to demonstrate compliance. They can also reduce the risk of twenty-seven national interpretations emerging around technical requirements that remain abstract. (European Commission)

Granting additional time can therefore be rational.

Requiring companies to complete conformity assessments using standards that have not been finalised would create legal uncertainty, unnecessary costs and inconsistent decisions.

The delay addresses a practical problem.

Its organisational interpretation may still become dangerous.

Sixteen months of relief or sixteen months of preparation?

Some companies will read the decision as follows:

“We have gained sixteen months. We will discuss the AI Act again in 2027.”

That sentence should trigger an alarm in every executive committee.

An organisation cannot build effective AI governance in a few weeks.

It must first know where its systems are.

In many companies, nobody has a complete view of the tools used by employees, contractors, subsidiaries, recruitment firms, software providers and operational teams.

One licence may have been purchased by IT.

Another may have been subscribed to directly by human resources.

An AI function may have been added to software that the company has used for years without being separately identified.

Employees may transfer information into public AI services without prior approval.

A provider may introduce an algorithmic feature during a contractual update.

An external recruitment firm may use an AI screening tool without its client fully understanding how it operates.

Before documenting risk, the organisation must discover reality.

The first project is an inventory

Every company should be able to answer a few basic questions.

Which AI systems interact directly with customers, applicants or employees?

Which systems only generate content?

Which systems recommend decisions?

Which systems make or automatically trigger decisions?

What personal data do they use?

Who approved their deployment?

Who monitors their outputs?

Who can stop them?

Who records incidents, errors and complaints?

Who responds when an affected person asks for an explanation?

A company unable to answer these questions does not yet have AI governance. It has a collection of tools with varying degrees of visibility.

The first useful deliverable is therefore not a forty-page policy.

It is a living inventory shared by business functions, IT, human resources, legal, compliance, security and executive leadership.

The GDPR is not taking a sixteen-month holiday

The postponement of certain AI Act requirements does not suspend other European rules.

Whenever a system processes personal data, the GDPR continues to apply.

The European Commission notes that individuals should generally not be subject to decisions based solely on automated processing when those decisions produce legal effects or similarly significant consequences, except in the situations and with the safeguards provided by the regulation. (European Commission)

The additional time for high-risk systems does not create a law-free zone.

A company currently using AI to analyse applicants, evaluate employees or assign scores remains responsible for its data processing, legal basis, proportionality and respect for individual rights.

The symbolic presence of a human at the end of a process may not be enough to turn an automated decision into a genuinely human one.

Clicking “approve” without understanding the system’s reasoning, data and limitations resembles automatic validation more than meaningful oversight.

AI literacy obligations have already started

The AI Act does not begin in August 2026.

Some provisions already apply.

Rules concerning prohibited practices and AI literacy have applied since 2 February 2025.

Providers and organisations deploying AI systems must take appropriate measures to give users a sufficient level of understanding, considering their experience, training and the context in which the systems are used. (European Commission)

Teaching employees how to write prompts does not address the entire requirement.

Teams must also understand model limitations, error risks, confidentiality, bias, human responsibility, prohibited uses and incident-reporting procedures.

A generic training course for everyone will rarely be enough.

Recruiters, developers, lawyers, salespeople and executive committee members do not make the same decisions with AI.

Compliance begins as process innovation

The adoption of artificial intelligence is fundamentally a form of process innovation.

It transforms how companies recruit, produce, decide, communicate, serve customers and organise work.

Buying a licence is insufficient.

Deploying a chatbot does not constitute a strategy.

Adding AI to an outdated process may simply accelerate a poor process.

The organisation needs a vision, a strategy, defined responsibilities, experimentation methods, decision rules, control mechanisms and a capacity for collective learning.

I address this transformation in my book, Chapter 14, which applies the Innovational Intelligence® system to artificial intelligence.

The regulatory challenge and the managerial challenge therefore converge.

An organisation that does not know who decides, controls, documents and assumes responsibility will encounter the same difficulties with compliance that it already experiences with innovation.

Leaders have been given a strategic window

The additional sixteen months can be used to build useful governance rather than defensive bureaucracy.

The period can be used to:

  • map systems and use cases;
  • classify risks according to real consequences;
  • appoint an accountable owner for each system;
  • review supplier contracts;
  • document data, models and decisions;
  • test performance and bias;
  • create credible human-oversight mechanisms;
  • train teams according to their responsibilities;
  • design challenge, appeal and shutdown procedures;
  • connect AI governance with existing security, quality and compliance systems.

This work creates immediate value, even before every new requirement applies.

It reduces errors.

It clarifies responsibility.

It improves decision quality.

It strengthens the confidence of employees, applicants and customers.

It also helps distinguish genuinely useful projects from opportunistic experiments launched because an executive watched an impressive demonstration.

2027 has already begun

The most intelligent companies will not treat 2 December 2027 as a starting date.

They will treat it as an arrival date.

They will use the coming months to learn, experiment, document, correct and build an organisation capable of controlling its own systems.

Others will probably wait until a customer asks a difficult question, an applicant challenges a decision, a supplier refuses to provide documentation or an audit discovers several unknown tools.

They will then discover that compliance cannot be purchased at the last minute like a software licence.

The European paradox may ultimately prove useful.

The chatbot will have to reveal its identity.

The company will also have to reveal its own: its vision, responsibilities, rules and ability to assume accountability for decisions made with artificial intelligence.

Does your company already know which AI systems speak to people and which ones make decisions about them?

References

Picture of Philippe Boulanger

Philippe Boulanger

Philippe Boulanger, international speaker on innovation and artificial intelligence, author, advisor, mentor and consultant.

Latest POSTS

Moat vs unfair advantage: what’s the real difference?

An unfair advantage protects you today. A moat protects you five years from now. Here’s how to tell which one you actually built, and how to turn the first into the second.

Read More »

The 5 Whys Method: The Tool That Stops You From Lying to Yourself

A tool born in a 1930s Japanese textile factory can stop you from lying about the real cause of your professional roadblocks. Here’s how to apply it, step by step.

Read More »

Dr Fox Effect: When Charisma Beats Competence at Work

An untrained actor got 55 specialists to applaud a meaningless lecture. The Dr Fox effect explains why your meetings reward charisma over facts, and why the same trap awaits voters as the next election approaches.

Read More »

Dunning-Kruger Effect: The Lemon Juice Bank Robber

In January 1995, a bank robber coated his face in lemon juice, sure it would make him invisible to cameras. His story gave birth to the Dunning-Kruger effect, the bias that makes the least competent feel like the best. Here is why it sabotages your innovation and management decisions, and how to neutralize it.

Read More »

AI Was Supposed to Kill Google. It Made It Huge.

ChatGPT was supposed to bury Google. Three years later, Alphabet is worth $4.3 trillion, Gemini is nearing 900 million users and cloud is growing more than 80%. Autopsy of a death foretold that never happened, and the lesson for your company.

Read More »

A dead generator and twelve silent engineers

Two days spent listening to a machine, one chalk mark, and a 10,000-dollar invoice. The true story behind the myth of the paid-to-think employee, and what it says about intellectual capital in the age of AI.

Read More »

One Word Sold the iPhone: The Steve Jobs Playbook

Steve Jobs did not describe the iPhone, he framed it. A single verb, reinvent, moved the audience from comparison to transformation. Here is the perception mechanism behind that choice, and how to apply it to your next launch.

Read More »

Why a patent doesn’t guarantee market success

More than 4,400 mousetrap patents, and almost no success. From the Segway to the Betamax, why a legal monopoly never guarantees a market, and what a leader must check before filing.

Read More »

Are you a rule breaker?

You weren’t supposed to find this.

But here you are, because you did what most people don’t: you questioned, you explored, you clicked the thing you weren’t sure you should click.

That’s Innovational Intelligence™ in action.

Most people stay inside the lines. Follow the expected path. Click the obvious buttons. Accept things as they are.

Not you.

You’re one of those rare minds that refuses to accept “this is how it’s always been done.”

We need more people who think like you.

So here’s your reward for coloring outside the lines:

Get VIP pre-release access to the next assessment on Innovational Intelligence™:

You’ll be the first to know when it’s available.

Keep breaking rules. The world needs what you see.