“High-risk” is EU vocabulary, and a plain customer chatbot usually isn't on that list — but a separate, lower EU tier still reaches it, and Canada uses neither term.
Short answer
Usually not “high-risk” in the EU sense, but that isn't the end of it. “High-risk” is a defined category under the EU AI Act's own scheme, and a general customer chatbot doesn't fall into the enumerated high-risk areas. But the EU Act has a separate transparency tier that catches any AI system meant to interact with people directly — chatbots included — and Canada has no equivalent tiering system in force to answer this question with at all.
These are two different regimes and two different words, and mixing them up is one of the most common ways to get this wrong. “High-risk” is the EU AI Act's term, tied to an enumerated list of use cases — things like AI safety components in critical infrastructure and systems that determine access to education or employment. Canada's proposed AIDA, which never became law, used a different term entirely: “high-impact” AI systems. Federal policy that does exist and is in force, the Voluntary Code of Conduct, also uses “high-impact,” not “high-risk” — the Code describes many of its measures as “broadly applicable to a range of high-impact AI systems”. A generic customer chatbot is not, on its own, in either camp's most-scrutinized tier.
This part is EU law, included because the question is framed in EU terms — no Canadian regulator enforces it. Article 50(1) of the EU AI Act creates a transparency duty that applies whether or not a system is high-risk: “Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious…” That duty is triggered by the interaction itself, not by a risk classification, so a plain customer-service chatbot can be caught by Article 50 while sitting entirely outside the Act's high-risk list.
In Canada, there is no operating “high-risk” or “high-impact” classification in force for a private business's chatbot to fall into, because AIDA never passed committee. The nearest real Canadian analogue is the Treasury Board's Directive on Automated Decision-Making, and it explicitly does not apply to private businesses — it binds federal government departments using an automated system to make “an administrative decision or a related assessment about a client.” A private-sector chatbot answering customer questions sits outside every Canadian risk tier that currently has legal force. What does still apply is ordinary Canadian law: PIPEDA if the chatbot handles personal information, and the Competition Act if what it tells customers is a representation a business is responsible for. A due-diligence review is the right place to work through which of those actually bind a specific deployment.
See what a diligence review checks before a regulatory label becomes a surprise.