Treadstone Associates
Ask an Expert · 3 min read

Is a customer chatbot a high-risk AI system?

“High-risk” is EU vocabulary, and a plain customer chatbot usually isn't on that list — but a separate, lower EU tier still reaches it, and Canada uses neither term.

Treadstone Associates · Updated 2026

Short answer

Usually not “high-risk” in the EU sense, but that isn't the end of it. “High-risk” is a defined category under the EU AI Act's own scheme, and a general customer chatbot doesn't fall into the enumerated high-risk areas. But the EU Act has a separate transparency tier that catches any AI system meant to interact with people directly — chatbots included — and Canada has no equivalent tiering system in force to answer this question with at all.

Don't merge “high-risk” with “high-impact”

These are two different regimes and two different words, and mixing them up is one of the most common ways to get this wrong. “High-risk” is the EU AI Act's term, tied to an enumerated list of use cases — things like AI safety components in critical infrastructure and systems that determine access to education or employment. Canada's proposed AIDA, which never became law, used a different term entirely: “high-impact” AI systems. Federal policy that does exist and is in force, the Voluntary Code of Conduct, also uses “high-impact,” not “high-risk” — the Code describes many of its measures as “broadly applicable to a range of high-impact AI systems”. A generic customer chatbot is not, on its own, in either camp's most-scrutinized tier.

The EU's separate, lower tier still reaches a chatbot

This part is EU law, included because the question is framed in EU terms — no Canadian regulator enforces it. Article 50(1) of the EU AI Act creates a transparency duty that applies whether or not a system is high-risk: “Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious…” That duty is triggered by the interaction itself, not by a risk classification, so a plain customer-service chatbot can be caught by Article 50 while sitting entirely outside the Act's high-risk list.

What a Canadian business actually has to check

In Canada, there is no operating “high-risk” or “high-impact” classification in force for a private business's chatbot to fall into, because AIDA never passed committee. The nearest real Canadian analogue is the Treasury Board's Directive on Automated Decision-Making, and it explicitly does not apply to private businesses — it binds federal government departments using an automated system to make “an administrative decision or a related assessment about a client.” A private-sector chatbot answering customer questions sits outside every Canadian risk tier that currently has legal force. What does still apply is ordinary Canadian law: PIPEDA if the chatbot handles personal information, and the Competition Act if what it tells customers is a representation a business is responsible for. A due-diligence review is the right place to work through which of those actually bind a specific deployment.

Evaluating a customer-facing AI tool?

See what a diligence review checks before a regulatory label becomes a surprise.