AI
AI Assistant Regulation and User Rights
A practical guide to the EU AI Act’s four risk levels, vendor-documented privacy controls, and a six-step way to check your own regulatory questions.
Sources checked 2 Oct 2026
Vendor pages settle only part of AI Assistant Regulation and User Rights. OpenAI’s data-controls page documents account, training, memory and temporary-chat controls; Anthropic’s training page says incognito chats are excluded from model improvement; Google’s Gemini Apps Privacy Hub identifies regional Gemini providers. The European Commission’s AI Act overview and ICO guidance describe risk, transparency, accuracy and fairness, but do not certify an assistant for a particular use. Chat Picker has not tested ChatGPT, Claude or Gemini for compliance, accuracy or user-rights handling.
What the vendors document
The regulatory starting point is the use, not the assistant’s brand. The European Commission’s AI Act overview, as read on October 1, 2026, says the Act defines four risk levels. It bans AI systems considered a clear threat to safety, livelihoods or rights and lists individual criminal-offense risk assessment or prediction among nine prohibited practices. The first eight prohibitions became effective in February 2025; the ninth is set for December 2026. Education, employment and credit scoring appear among high-risk uses. The page says people should be made aware that they are interacting with a machine and that generated content must be identifiable under transparency rules. It also says authorities conduct market surveillance and providers and deployers report serious incidents and malfunctions.
The Commission says general-purpose AI obligations applied on August 2, 2025, and its enforcement powers apply on August 2, 2026. Its GPAI provider guidelines are not legally binding but reflect its interpretation; providers of the most advanced models posing systemic risks must notify the AI Office. The ICO guidance, as read on October 1, 2026, was updated March 15, 2023 and is under review because of the Data (Use and Access) Act. It calls statistical accuracy key to fairness, covers possible bias across the AI lifecycle and points to high-level transparency guidance.
As read on October 1, 2026, OpenAI’s pricing page lists a model-improvement opt-out for Free, Go, Plus and Pro, but no exact message counts. OpenAI’s data-controls page says signed-in users on those consumer plans can request a data copy and delete their account; managed users must contact the workspace owner. Turning off model improvement does not delete saved chats. Temporary chats stay out of history and memory, are not used for model improvement and may be retained for up to 30 days for safety.
Anthropic’s pricing page says model improvement is optional on Free, Pro and Max, and Team is not trained on by default. Its training page says chats and coding sessions are used to improve models when allowed, while incognito chats are excluded; conversations flagged for safety review may also be analyzed. Google’s personalization page says personalization requires a personal Google Account, is unavailable to work, school and supervised accounts, and is not available to everyone. Google’s Privacy Hub identifies Google Ireland Limited as the Gemini Apps provider in the European Economic Area and Switzerland and Google LLC elsewhere, but does not state a model-improvement setting.
For accuracy, OpenAI says ChatGPT can be incorrect or confident when wrong and advises checking important information from reliable sources. Claude’s accuracy notice says not to use it as the only source of truth and to inspect original websites. Gemini’s source page says a Sources button appears when sources are available, but the cited material does not say those sources are complete.
What the documentation cannot tell you
These pages cannot classify your actual use without facts about its purpose, affected people, geography, data and human involvement. A controlled trial can show what one account did with one prompt; it cannot establish consistent accuracy, fairness or legal compliance.
The cited regulatory pages do not create a universal complaint route or settle a GDPR request, and vendor pages describe settings rather than legal advice. Check your contract, account settings and applicable regulator materials. This is general information, not legal advice.
How to check it yourself
Use synthetic records and identical task wording rather than confidential material.
-
Classify the use. Paste the Commission page, then ask: “A customer-service team in France buys a product marketed as a general-purpose assistant to summarize complaints and draft nonbinding replies for human approval. Explain which EU AI Act risk questions must be answered, separate documented rules from missing facts, cite the page and do not assign a final legal category.” Look for “prohibited,” “high risk” and “minimal or no risk.” Write down the purpose, affected people, location and reviewer’s role.
-
Separate features from legal rights. Paste the ICO guidance and the three vendors’ account pages linked above. Ask: “Compare access, correction, deletion, export and model-use controls. Label each item as a vendor feature or a legal right supported by the pasted text, and mark anything not established.” Look for that distinction. Record the setting, plan, region, workspace status and unanswered legal question.
-
Check transparency and model cards. Give the assistant OpenAI’s accuracy page, Claude’s accuracy notice and Gemini’s source page. Ask: “List every statement about intended use, known limits, source access, human review and accuracy. State whether each page supplies or links a model card; do not infer missing claims.” Write down what is explicit, conditional or absent.
-
Test cross-border questions. Paste Google’s Privacy Hub, then ask: “A person opens Gemini in France and later uses the same personal account from the UK. Identify only the provider entities, processing locations and transfer terms stated in this notice; list each missing fact.” Record what the notice establishes and what you still need to verify.
-
Probe fairness. Give the assistant this scenario and the pasted ICO guidance: “A hospital uses an AI assistant to screen 20 synthetic applications for a job in Italy. Group labels and unrelated image traits correlate with ranking, but protected fields are absent. Explain what can and cannot be inferred, propose audit checks and avoid claiming legal compliance.” Look for group-specific error checks and contextual review. Record the variables, outcomes, reviewer process and evidence needed.
-
Find an escalation route. Paste the Commission page and the three vendor account pages. Ask: “A synthetic medical document appears in the wrong chat. List any documented complaint, support, incident-report or regulator route. Separate those routes and state what is missing.” Look for a named recipient rather than “contact support.” Record the route, scope, jurisdiction and any deadline the source actually states.
Which rows of the comparison matter
Open the ChatGPT, Claude and Gemini comparison matrix. Prioritize these rows:
- Training on your chats: check the documented choice first; treat “Not verified” as unresolved.
- Free plan, Low-cost tier, Main paid plan, Heavy-use plans and Team plan: these identify the plan and workspace context in which you should test account controls.
- How usage limits are described: distinguish published counts from broad descriptions such as “expanded” or “more” usage.
- Context window in the app: this can flag model variation, but it does not establish legal status or user rights.
A blank cell is not evidence that a feature is absent. Confirm material claims on the linked vendor page, and use regulatory materials for legal questions.