Quick answer
A chatbot is a program you talk to by text or voice instead of clicking through menus and filling in forms. There are three main types: rule-based bots (scripts and decision trees), assistants built on large language models (LLMs) that understand free-form language, and hybrid systems that combine both with search over company documents. In 2026 a good business chatbot is most often a hybrid: the LLM handles the conversation, facts come from company sources, and sensitive actions go through rules or a human.
What exactly is a chatbot?
A chatbot is a program that holds a conversation with a person and, based on it, answers questions or performs simple actions. Instead of hunting for information in menus, the user types or says what they need and gets an answer right away.
The broader term is conversational AI: the technologies that let machines understand natural language and hold a dialogue, from speech recognition to answer generation.
The idea is not new. Back in 1966, Joseph Weizenbaum at MIT described ELIZA, a program that carried on a conversation by matching patterns in what the user typed (Weizenbaum, 1966). For decades after that, chatbots ran mostly on rules. Large language models were the breakthrough that let bots understand questions phrased any way at all, not just those anticipated in a script.
An example: a customer of an online clothing store is looking for something to wear to a summer wedding. Instead of scrolling through hundreds of dresses, they describe what they need in the chat window. The chatbot asks about style, budget, and the formality of the event, checks inventory, and suggests a few matching options with size recommendations. If a size is out of stock, it offers an alternative or a restock alert.
What types of chatbots are there?
Chatbots differ in how they understand the question and where the answer comes from, even if they look alike to the user.
Rule-based bots follow scripts and decision trees. They look for specific words in the message and reply with stored text. Ask "What are your opening hours?" and the bot matches a rule and returns the hours. They are cheap, predictable, and easy to verify, but an unusual question ends with "Sorry, I don't understand."
Intent-based bots (classic NLP and machine learning) recognize what the user means, not just the words. "When can I come by?" and "Are you open this weekend?" map to the same intent. The answers are still prewritten, though, and every new intent has to be designed and trained.
LLM-based assistants use large language models (GPT, Claude, Gemini, or open models running locally). They understand context and tone, handle multi-turn conversations, and write their own answers. But the model on its own does not know your pricing, your terms, or the status of an order, and it can state falsehoods with total confidence.
Hybrid systems combine these approaches. An LLM runs the conversation, facts come from searching company documents (RAG), and sensitive actions such as account verification or refunds are handled by fixed logic or a person.
| Trait | Rule-based bot | Intent-based bot | LLM assistant | Hybrid (LLM, RAG, rules) |
|---|---|---|---|---|
| Understanding questions | Keywords only | Predefined intents | Free-form language and context | Free-form language and context |
| Source of answers | Prewritten text | Prewritten text | The model's own knowledge | Company documents and systems |
| Predictability | Very high | High | Low without guardrails | High for actions, flexible in conversation |
| Risk of made-up answers | None | Low | High | Limited by sources and checks |
| Maintenance | Manually extending scripts | Designing and training intents | Model fees, quality control | Knowledge base, integrations, monitoring |
| Best for | FAQs, simple forms | Repetitive requests from a limited set of categories | Internal tools, drafting | Customer and employee support on company data |
How does a modern LLM-based chatbot work?
Several layers sit behind the chat window, and the language model is only one of them. A typical flow looks like this:
- Channel. The message arrives from a website chat, a messaging app, email, or as a voice recording converted to text.
- Understanding the request. The model works out what the request is about and whether it is a question or a request for action.
- Retrieving knowledge. The system finds the relevant passages in company documents: terms, price lists, manuals. This is RAG (Retrieval-Augmented Generation). We explain how it works in how RAG makes AI smarter.
- Acting in systems. When needed, the chatbot calls APIs: it checks order status, an account balance, or available time slots.
- Checking the answer. The answer passes through filters: is it grounded in the sources, does it leak data, is it within the allowed scope?
- Handing off to a human. When the chatbot does not know the answer or the case is sensitive, the conversation goes to an agent with full context.
This is how our agentic knowledge base works: the agent searches the documents itself, every claim in the answer has a citation to a specific source passage, and before the answer is sent it passes a grounding check and a hallucination detector. The whole system can run on your own GPUs, so documents and questions never leave the company.
Which channels can a chatbot work on?
Wherever your customers and employees already talk:
- a chat window on your website or in your app, when typing is easiest,
- a voice assistant or phone bot, when speaking is easier than typing,
- messaging apps and email: WhatsApp, Messenger, SMS, the support inbox,
- internal tools: Slack, Teams, the intranet, for employee questions.
One engine can serve many channels. Our helpdesk agent takes tickets from email, SMS, and WhatsApp, assigns a category and priority, and performs sensitive actions only after a human approves them (AI agents).
What does a chatbot bring to a business and its customers?
Availability around the clock, many conversations at once, and faster answers to repetitive questions.
For the business: taking routine questions off the team, calmer peak periods, consistent answers, and data on what customers ask most often. A bank can answer an account question at night, a law firm can take an inquiry outside office hours, and a service company can pre-qualify a lead.
For the customer: help without waiting in a queue, on the channel they prefer, and the ability to handle common tasks on their own.
The most cited example of scale is Klarna. According to the company, its AI assistant handled 2.3 million conversations in its first month, two-thirds of its customer service chats, and the time to resolve an issue dropped from 11 minutes to under 2 (Klarna, 2024). What happened next is just as instructive: in May 2025 Klarna's CEO admitted that cost had been too dominant a factor, which led to lower quality, and the company started hiring people again so customers can always talk to a human (Customer Experience Dive, 2025). The lesson: a chatbot should take over routine work, not cut customers off from people.
What are the risks of a chatbot and how do you reduce them?
The biggest risk is a confident, wrong answer. And the company, not the chatbot, is responsible for it.
- Liability for content. In Moffatt v. Air Canada (February 2024), a Canadian tribunal held the airline liable for incorrect fare information its website chatbot gave a customer. The tribunal rejected the argument that the chatbot was a separate entity responsible for its own actions (Moffatt v. Air Canada, 2024 BCCRT 149). The fix: answer only from current documents, with a source.
- Disclosure duty (EU AI Act). Since August 2, 2026, people talking to a chatbot must be made aware that they are interacting with a machine (European Commission; AI Act, Article 50). The 2026 amendments postponed deadlines for high-risk systems, but not this obligation.
- Personal data (GDPR). Decide what data the chatbot may collect, where it is processed, and how long it is kept. When data cannot leave the company, the model can run locally.
- Manipulation by users. People can try to trick an LLM-based chatbot into breaking its rules with cleverly crafted instructions (prompt injection). We cover these threats and the defenses in our article on the OWASP Top 10 for LLM applications.
Chatbot, assistant, or AI agent?
The difference is how much the system can do on its own. A chatbot answers, an assistant helps you complete a task, and an AI agent takes actions in other systems by itself, such as opening a ticket or preparing a message to send. The line is blurring, because modern chatbots increasingly come with tools. More on this in AI agents vs agentic AI.
How do you start rolling out a chatbot?
With a narrow scope and your own knowledge sources, not with "a bot that answers everything."
- Pick the scope. A few categories of questions that take up most of your team's time today.
- Clean up your sources. Current terms, price lists, and manuals. A chatbot will never be better than the documents it draws on.
- Decide on actions. Which actions the chatbot performs itself, and which it only prepares for approval.
- Design the handoff to a human. A clear trigger and the full conversation context for the agent.
- Measure the right things. The share of conversations resolved without a human, answer accuracy on a sample, the number of handoffs, and user ratings.
The technology keeps changing fast, but the principle stays the same: a chatbot should guide the customer through the whole process, from question to resolved issue, based on knowledge the company can stand behind.
Sources
- Weizenbaum, J.: ELIZA, a computer program for the study of natural language communication between man and machine (Communications of the ACM, 1966)
- Klarna: Klarna AI assistant handles two-thirds of customer service chats in its first month
- Customer Experience Dive: Klarna changes its AI tune and again recruits humans for customer service
- Moffatt v. Air Canada, 2024 BCCRT 149 (CanLII)
- European Commission: AI Act, regulatory framework for AI
- Regulation (EU) 2024/1689 (AI Act)