Blog · Regulation affecting AI search visibility

Regulation and AI Search: GDPR, the EU AI Act and Visibility

Dharini Shah · September 19, 2026

Regulation affects AI search visibility in four practical ways: it governs how AI systems may use your content, what you must disclose when you use AI in customer-facing content and chatbots, how you collect data to measure AI-driven traffic, and what claims and reviews you can publish. For most brands, the biggest 2026 changes are the EU AI Act's transparency obligations, which applied from August 2, 2026, and the continued importance of copyright opt-outs, GDPR and consumer protection rules.

None of this makes AI visibility work illegal or impractical. It does mean that AEO and GEO programs need a compliance layer, especially for companies operating in the EU or in regulated industries. This article explains the rules that matter most and how they affect everyday AI visibility work.

This article is general information, not legal advice. Consult qualified counsel for your situation.

The EU AI Act: what applies in 2026

The EU AI Act entered into force in 2024 with obligations phased in over several years. In 2026, two developments matter.

The AI Omnibus delayed high-risk obligations. According to a Goodwin analysis, the AI Omnibus, Regulation (EU) 2026/1744, effective July 27, 2026, moved obligations for standalone high-risk AI systems to December 2, 2027, and for AI in regulated products to August 2, 2028.

Article 50 transparency obligations applied from August 2, 2026. These apply regardless of risk classification and include:

  • Disclosure of AI interaction: people must be informed they are interacting with an AI system unless it is obvious from context. This matters for brands deploying chatbots or AI agents on their sites.
  • Marking of synthetic content: providers of generative AI systems must mark outputs in a machine-readable format, with a grace period to December 2, 2026 for systems already on the market.
  • Deepfake disclosure: deployers must disclose deepfakes of real people and events.

Transparency violations can carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, according to the same analysis.

What this means for AI visibility work:

  • If you deploy an AI chatbot or agent on your website, disclose it clearly.
  • If you publish AI-generated images, video or audio that depict real people or events, follow deepfake disclosure rules.
  • Understand how the rules on text generated for public-interest information may apply to your content, and get advice where relevant.
  • Expect AI providers to mark their outputs; this does not change how you optimize for AI answers, but it may affect how AI-generated content you publish is identified.

In the EU, the Directive on Copyright in the Digital Single Market allows text and data mining of lawfully accessible content unless rights holders have expressly reserved their rights in an appropriate manner, such as machine-readable means for content made publicly available online. The AI Act requires providers of general-purpose AI models to have a policy to comply with EU copyright law, including respecting such reservations.

In practice, brands use robots.txt and similar controls to express preferences. The major AI providers separate training crawlers from search crawlers:

ProviderTraining controlSearch or retrieval crawler
OpenAIGPTBotOAI-SearchBot, ChatGPT-User
AnthropicClaudeBotClaude-SearchBot, Claude-User
GoogleGoogle-Extended tokenGooglebot for Search and AI features
PerplexityNot used for training, per its documentationPerplexityBot, Perplexity-User

Sources: OpenAI, Anthropic via Search Engine Land, Perplexity.

The visibility trade-off: blocking training crawlers is a legitimate choice to protect content. Blocking search crawlers removes you from AI search answers. OpenAI states that sites opted out of OAI-SearchBot will not be shown in ChatGPT search answers. Decide on each separately.

GDPR and AI visibility work

GDPR affects AI visibility programs in several places:

  • Measurement: tracking AI referral traffic with analytics cookies or similar technologies generally requires valid consent in the EU. Plan attribution with consent rates in mind; self-reported attribution and aggregated data help fill gaps.
  • Content: do not publish personal data, such as customer names in case studies or reviews, without a lawful basis and appropriate permissions.
  • AI tools: if you use AI tools to process customer data, for example to analyze support tickets for prompt research, ensure data processing agreements and appropriate safeguards are in place.
  • Accuracy about individuals: if AI answers repeat inaccurate personal information about your executives or staff, data protection rights may be relevant. Correcting sources remains the most practical first step.

Consumer protection: claims and reviews

AI visibility work often involves claims, comparisons and reviews, which consumer protection law regulates.

  • Fake reviews: in the U.S., the FTC's rule on consumer reviews and testimonials, announced in August 2024, prohibits fake reviews including AI-generated ones, sentiment-conditioned incentives, undisclosed insider reviews and review suppression, and allows civil penalties. EU consumer law also prohibits fake reviews.
  • Claims substantiation: superlatives and comparative claims written to influence AI answers are still advertising claims and must be truthful and substantiated.
  • Sector rules: finance, health, legal services, housing and education have additional rules.

Advertising in AI answers

OpenAI began testing ads in ChatGPT in February 2026 and expanded to 31 European markets in August 2026. OpenAI states that ads are labeled, separate from answers, do not influence answers, and that advertisers do not have access to users' chats or personal details. Advertisers remain responsible for complying with advertising and data protection law in each market.

A compliance checklist for AI visibility programs

Common mistakes

Blocking all AI bots for "compliance." Most rules do not require it, and it removes search visibility.

Undisclosed chatbots. Article 50 requires disclosure unless AI interaction is obvious.

Ignoring consent in AI attribution. Tracking without consent creates legal risk and unreliable data.

Review shortcuts. Increasingly enforced on both sides of the Atlantic.

A hypothetical example

A hypothetical European ecommerce brand reviews its AI visibility program ahead of August 2026. Its robots.txt blocks all AI user agents, a rule added in 2023. Its website chatbot does not state that it is AI. Its AI referral tracking fires before consent. The brand unblocks AI search crawlers while keeping training crawlers blocked, adds a clear AI disclosure to its chatbot, moves AI referral tracking behind consent and supplements it with a post-purchase survey question about how customers found them.

How Bob Builds AI approaches compliance

Bob Builds AI's Agent Analytics helps teams see which AI crawlers access their sites, which supports informed crawler policies, and approval workflows through its integrations help keep claims under review before publication.


FAQ

What does the EU AI Act require from website owners?

For most website owners, the key 2026 obligation is transparency under Article 50: if you deploy an AI system that interacts with people, such as a chatbot, you must inform users they are interacting with AI unless it is obvious. Deepfake content must be disclosed. Other obligations depend on your role and use case.

When did the EU AI Act transparency rules apply?

Article 50 transparency obligations applied from August 2, 2026. The AI Omnibus postponed high-risk obligations to December 2, 2027 for standalone systems and August 2, 2028 for AI in regulated products.

Yes, with most major providers. OpenAI separates GPTBot from OAI-SearchBot, Anthropic separates ClaudeBot from Claude-SearchBot, and Google offers the Google-Extended token for Gemini training while Search uses Googlebot. Configure each separately.

Does GDPR affect tracking AI referral traffic?

Yes, in the EU, analytics tracking generally requires valid consent. Design AI attribution with consent in mind and supplement it with aggregated data and self-reported attribution.

Fake reviews, including AI-generated ones that misrepresent a real customer's experience, are prohibited under the FTC's 2024 rule in the U.S. and under EU consumer law. Reviews must reflect genuine experiences.

Do ads in ChatGPT use personal data?

OpenAI states that advertisers do not have access to users' chats, chat history, memories or personal details, and that users can manage ad personalization. Advertisers remain responsible for complying with advertising and data protection laws.

Does regulation limit AEO and GEO work?

Not fundamentally. It adds a compliance layer: separate crawler decisions, disclosures for AI systems you deploy, consent-aware measurement, lawful use of personal data and substantiated claims and reviews.


Conclusion

Regulation shapes AI visibility work at the edges rather than at the core. The EU AI Act's transparency rules, copyright opt-outs, GDPR and consumer protection law determine how you disclose AI use, control training access, measure traffic and make claims, while the fundamentals of clear, accurate and corroborated content remain unchanged.

Start by reviewing three things: your robots.txt decisions for training versus search crawlers, disclosures on any AI chatbot you run and consent for AI referral tracking. Bob Builds AI can help you see which AI crawlers reach your site as you refine those policies.

All posts
Regulation affecting AI search visibilityEU AI Act Article 50AI Omnibus delaysGDPR and AI marketingText and data mining opt-outs

Don't just sit with what AI says about your brand.
Fix it now with Bob Builds.

Book a demo