The AI missing from our AI register was the only one the public could talk to
The EU AI Act transparency rules came into force on Sunday, so yesterday I went and checked a help docs site I maintain. It has a chat assistant on it that answers questions from the documentation. Nothing exotic.
Article 50 says that if a system interacts directly with a person, that person has to know they are talking to a machine, at or before the first interaction.
Ours opened with "Hi, what can I help you with?" and the button said "Ask the help assistant". Nowhere did it say AI. That is a five minute fix and worth doing, because "help assistant" is exactly what a human support team gets called, and ours tells people to email a human inbox when it cannot answer. Somebody could reasonably believe they were already in a queue with that team.
That was not the interesting part.
While I was in there I checked our AI register, which is the document you hand someone when they ask what AI you run. Eight systems on it. All internal scheduled agents: support triage, lead monitoring, a reporting job. Each with a lawful basis, a risk rating, a review date.
The chat widget was not on it. The only public, unauthenticated, customer facing AI we run was the one system missing from the list.
Nobody was careless. The register was built by going through the agents, because those feel like AI systems. They have schedules and API keys and a folder on a machine. A chat widget on a website feels like a website feature. It arrived through a different door, so it never got counted.
That is the bit I think generalises beyond compliance paperwork. An inventory is a list of the things you were already thinking about on the day you wrote it. The gap is not in the entries, it is in how the list was gathered, and that is invisible from inside the list. Ours looked complete. It had IDs, a version number and a review schedule. Complete and wrong look identical.
So, two questions, both cheap, and I suspect more people find something than expect to.
Open your own product and look at whatever chat or assistant you have in it. Does it say it is AI before someone types into it?
Then: whatever list you would hand a person who asked what AI you run, is that thing on it? And was the list built by surveying your surfaces, or by remembering your systems?
One practical note, since most of the posts about this are about the wrong rule. The labelling obligation everyone is discussing is narrow and applies to content published to inform the public on matters of public interest. The chatbot one has no such limit. Far more of us have a chat widget than publish public interest content.
Replies