If your business books appointments through a WhatsApp bot powered by artificial intelligence, there's a rule you need to know about: since August 2, 2026, any AI chatbot serving people in the European Union has to disclose that it's an AI, clearly and from the very first message. It comes from Article 50 of the EU AI Act, and it doesn't matter whether your clinic, salon or restaurant is based in Dublin, Toronto or Los Angeles — if you're talking to customers in the EU, it applies to you. Here's exactly what the rule requires, what changes if your business sits outside the EU, and how to comply without rebuilding your bot from scratch.
What is the AI Act, and why does it apply to a booking bot?
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's first comprehensive AI law. It entered into force in August 2024, but its obligations roll out in stages based on risk: prohibited practices first, high-risk systems next, and now it's the turn of the transparency obligations in Article 50, which took effect on August 2, 2026.
That article isn't about high-risk sectors or healthcare specifically: it covers any AI system that interacts directly with a person. A WhatsApp bot that confirms a booking, reschedules an appointment or answers availability questions falls squarely inside that definition, however simple it looks.
The law separates the provider (whoever builds the system — Cruslar, in the case of Aura or DineSync) from the deployer (whoever puts it in front of customers — your business). The provider has to make the disclosure possible; the business using it has to make sure it actually shows up.
What does your bot actually have to say, and when?

The rule is specific: the disclosure has to be clear and distinguishable, and it has to arrive at first contact — not buried in a privacy policy nobody opens. Naming the bot "Virtual Assistant" in the WhatsApp profile isn't enough on its own: if a reasonable person could mistake it for a human mid-conversation, the disclosure needs to be inside the message itself.
Wording that works:
- "Hi, I'm [business]'s automated assistant. I can help you book, change or cancel your appointment. Ask for a person any time."
- "This chat is handled by an AI assistant. Type 'talk to a person' whenever you'd like."
Wording that doesn't: a bot that simply replies naturally without ever stating it's an AI, even if it "sounds" automated. The rule requires it to be explicit, not implied.
There's one exception: if it's already obvious to a reasonably informed person that they're talking to AI — think a clearly robotic voice on an old-school phone menu — an explicit disclosure isn't required. A WhatsApp bot that writes like a person doesn't qualify for that exception: by design, it mimics a human conversation, so the disclosure is required almost every time.
Does this apply if your business isn't in the EU?
This is the part most businesses miss: the AI Act doesn't look at where your business is — it looks at where your customer is. If you're talking to people in the European Union over WhatsApp, Article 50 applies even if your company is registered in London, Miami or Toronto. Outside the EU, the picture changes by region:
| Region | What applies today | Maximum penalty |
|---|---|---|
| EU / Spain | AI Act, Art. 50 (mandatory) | €15M or 3% of turnover |
| UK / Ireland | No dedicated law; AI Act applies if you serve EU customers | Depends on the sector regulator |
| US / Canada | No federal law; 11 US states have their own (incl. California) | Depends on the state |
The UK doesn't have an AI Act equivalent yet: sector regulators like the ICO (data protection) and the FCA (financial services) enforce transparency through their own consumer-protection rules instead. But if your Dublin clinic or London restaurant also serves customers inside the EU — common for cross-border or online-booking businesses — the AI Act reaches you through that route regardless.
In the United States there's no federal chatbot transparency law, but eleven states already have their own, starting with California, whose B.O.T. Act (SB 1001) requires disclosure when a bot interacts with commercial intent. Canada doesn't currently have a specific federal law on this either — the bill that would have addressed it stalled — so there's no equivalent national requirement for now.
What happens if you don't disclose it
The financial penalty is real — up to €15 million or 3% of worldwide turnover under the EU AI Act — but for an appointment-based business, the bigger risk is trust. Booking an appointment at a clinic or a table at a restaurant means sharing personal details, sometimes sensitive ones. If a customer later finds out they were talking to an AI without being told, the reaction isn't "impressive technology" — it's "what else weren't they upfront about?"
Worth noting: the disclosure isn't only a legal box to tick. Done well, it's also the fastest way for a customer to know they can ask for a human whenever they need one, which heads off complaints and confusion before they happen.
How Aura and DineSync already handle this

At Cruslar we built Aura, our AI WhatsApp assistant for appointment-based businesses, and DineSync, for restaurant bookings, with the transparency disclosure built into the first message of every new conversation — not a setting you have to remember to turn on. But how much detail you actually need changes with the stage your business is at:
- If you're just starting out or testing the bot, a fixed disclosure at the start of the conversation plus a clear path to a human is enough to comply. Nothing custom needed yet.
- If you already run several locations or a high volume of bookings, it's worth going further: disclosure adapted to each customer's language, a record of when it was shown (in case a regulator asks), and a human handoff that actually works, not just one that exists on paper.
- Confirm your bot falls under the AI Act: if it talks or writes to real customers, it does, whatever AI is running behind it.
- Add the disclosure to the first message of every new conversation, not the profile bio or the privacy policy.
- Keep a visible path to a human that actually works, not just one that's mentioned.
- Check the disclosure in every language you serve customers in: a Spanish-only notice doesn't help an English-speaking customer.
- Keep a record of when you turned it on: a screenshot or a dated log is enough if you're ever asked.
Frequently asked questions
Does the AI Act apply to me if my business isn't in the EU?
It depends on who you're talking to, not where your business is based. If your bot talks to customers in the EU, Article 50 applies even if your company is elsewhere. If you only serve customers outside the EU, check your own country's or state's law instead.
Is naming the bot "Virtual Assistant" in the WhatsApp profile enough?
Not necessarily. The law wants the disclosure inside the conversation itself, at first contact — not just in the visible profile name.
Do I need customer consent before they talk to the bot?
Article 50 requires disclosure, not the kind of explicit consent that data protection law (like GDPR) requires for certain data. They're separate obligations: the AI Act is about transparency, GDPR is about what data you can collect and how you handle it.
Is there a grace period before penalties can apply?
No. Article 50 took effect on August 2, 2026, and each country's market surveillance authority can already enforce it from that date.
Does this apply to a restaurant booking bot too, not just medical or beauty appointments?
Yes. The AI Act doesn't distinguish by sector: it applies to any AI system that interacts with people, whether it's managing a beauty appointment, a restaurant table or any other service.
If you're using or considering an AI-powered WhatsApp bot for bookings or appointments, we can review whether your disclosure meets the AI Act and help you add it without rebuilding the bot. It's part of our IT solutions, alongside other changes Meta is already rolling out for WhatsApp Business. Got questions? Get in touch.