The AI Act has direct implications for omnichannel customer service: anyone who uses AI for customer interactions via phone, chat, email, or WhatsApp falls under the regulation and must comply with transparency requirements—and, in some cases, more stringent compliance requirements. The law will take effect in phases and imposes obligations on both providers of AI systems and the organizations that use these systems on a daily basis. Below, we answer the most frequently asked questions about what the AI Act specifically means for your customer service organization.
Which AI applications in customer service are covered by the AI Act?
Most AI applications in customer service fall into the “limited risk” or “minimal risk” category, which means they are subject to relatively light regulatory obligations. Examples include chatbots, virtual assistants, and automated email processing. However, as soon as an application profiles customers, evaluates them, or makes decisions that affect their access to services, you move into the high-risk category.
Specifically, these are the most common AI applications in omnichannel customer service and how they are categorized:
- Chatbots and virtual assistants: Limited risk. Transparency requirements apply: Customers must be informed that they are communicating with an AI.
- Automatic call routing based on customer profile: Potentially high risk if the system performs profiling or influences access to services.
- Sentiment Analysis and Emotion Recognition: Please note: Emotion recognition in the workplace is prohibited under Article 5, unless a medical or safety exception applies.
- AI-driven employee quality monitoring: Falls under employment and human resources management (Annex III), which classifies it as high-risk.
- Automated response suggestions for agents: Generally low risk, provided that the agent makes the final decision.
The key question is always: Does the system make decisions that significantly affect the customer or employee, or does it merely support a human decision? When in doubt, it is wise to seek legal advice and document the system.
What are the requirements for high-risk AI in customer interactions?
If an AI system used in customer interactions is classified as high-risk, extensive obligations apply. The most stringent requirements fall on the system provider, but you, as the deployer (the organization implementing the system), also have specific responsibilities.
Requirements for Providers of High-Risk AI
Suppliers must establish an ongoing risk management system, maintain technical documentation, enable automatic event logging, and design the system in such a way as to ensure effective human oversight. In addition, a conformity assessment, CE marking, and registration in the EU database are mandatory.
Requirements for Deployers (Customer Service Organizations)
If you use a high-risk AI system in your customer service operations, you are considered a deployer and are subject to the following obligations:
- Use the system in accordance with the provider’s instructions for use.
- Assign human supervision to qualified and trained employees.
- Keep logs for at least six months.
- Inform employees before the equipment is put into service (Article 26(7)).
- Where applicable, conduct a data protection impact assessment (DPIA).
Customers who are subject to a decision made by a high-risk system may, pursuant to Article 86, request an explanation of the determining factors. This has direct implications for how you structure your customer communications and appeal procedures.
When will the AI Act take effect for customer service organizations?
The AI Act is being implemented in phases, and the most relevant deadlines for customer service organizations in 2026 are either already in effect or just around the corner. As of February 2, 2025, the prohibitions in Article 5 and the AI literacy requirement will already be in effect. This means that prohibited applications, such as manipulative AI or emotion recognition in the workplace, are already not allowed.
The timeline that is most relevant for customer service:
- February 2, 2025 (already in effect): Prohibited Practices (Article 5) and AI Literacy Requirement (Article 4). Ensure that your employees have a basic understanding of the AI systems they work with.
- August 2, 2025 (already in effect): Requirements for large language models and penalty provisions are in effect. Do you use large language models in your customer service? If so, transparency requirements already apply.
- August 2, 2026 (upcoming deadline): Most requirements for high-risk Annex III systems will become enforceable. This is the most critical deadline for many customer service organizations.
- August 2, 2027: Additional requirements for high-risk AI used as a safety component in regulated products.
Practical advice: Start keeping a record of all the AI systems you use right away, determine your role for each system (provider, deployer, importer, or distributor), and verify that the provider of your systems is complying with its obligations.
What are the consequences of noncompliance with the AI Act?
The fines for noncompliance with the AI Act are substantial and will take effect on August 2, 2025. The amount depends on the severity of the violation and is calculated based on global annual revenue or a fixed amount, whichever is higher.
The three levels of sanctions:
- Violations of prohibited practices (Article 5): Up to 35 million euros or 7% of global annual revenue.
- Non-compliance with other obligations: Up to 15 million euros or 3% of annual revenue.
- Inaccurate or misleading information provided to authorities: Up to 7.5 million euros or 1% of annual revenue.
In addition to financial risks, there are also operational and reputational risks. If a customer requests an explanation of an AI decision under Article 86 and you are unable to provide it, this could lead to complaints filed with regulators. In January 2026, Finland became the first EU member state to grant enforcement powers to its national authority, indicating that enforcement is rapidly approaching.
How do you prepare an omnichannel customer service operation for AI Act compliance?
Preparing an omnichannel customer service operation for AI Act compliance requires a structured approach: first, identify which AI systems you use, determine the risk category for each system, and then establish the corresponding governance framework. Start with the most urgent requirements that are already in effect.
A practical step-by-step guide:
- Create an AI registry: Document all the AI systems you use in your customer service operations, from chatbots to routing software and quality monitoring.
- Determine your role for each system: Are you a provider, deployer, importer, or distributor? Your obligations vary depending on your role.
- Classify the risk: Is the system high-risk (e.g., profiling or decisions regarding access to services)? Or does it fall under the category of limited risk with transparency requirements?
- Check your suppliers: Ask AI system providers for declarations of conformity and technical documentation. Are they CE-marked for high-risk systems?
- Train your employees: The AI literacy requirement (Article 4) is already in effect. Make sure employees understand how the AI systems they use every day work.
- Establish human oversight: For each high-risk system, designate a qualified person to monitor it and maintain logs.
- Integrate AI Act compliance into your GDPR processes: Many requirements overlap, such as the DPIA requirement and logging.
Organizations that are already working with fragmented systems from multiple vendors face an additional risk: it is difficult to ensure compliance if you do not have a centralized overview of which AI functionality is active in which channel.
What does the AI Act mean for customers who contact us through multiple channels?
For customers who contact us through multiple channels, the AI Act provides a number of specific rights and protections. The law strengthens the customer’s position vis-à-vis automated systems, particularly when AI decisions affect the services they receive.
The most relevant consumer rights in an omnichannel context:
- Right to an Explanation: Customers who are subject to a decision made by a high-risk AI system (such as automated prioritization or referral) may, pursuant to Article 86, request an explanation of the determining factors.
- Transparency Regarding the Use of AI: When a customer communicates with an AI system via chat or phone, it must be clear that the system is not a human. This requirement already applies under the transparency obligations for low-risk AI.
- Protection against manipulation: AI systems may not use subliminal or manipulative techniques to influence customer behavior. This prohibition has been in effect since February 2, 2025.
- Protection of Vulnerable Groups: AI must not exploit vulnerabilities based on age, disability, or socioeconomic status. This is relevant for customer service in sectors such as healthcare, government, and housing authorities.
For organizations with an omnichannel approach, this means you must check for each channel which AI is active and which transparency requirements apply. A customer who starts on WhatsApp, switches to the phone, and then receives an email must be provided with the correct information at every touchpoint regarding whether and how AI is being used.
How Pegamento Helps Ensure AI Act Compliance in Omnichannel Customer Service
We understand that AI Act compliance presents an additional challenge for many customer service organizations on top of their day-to-day operations. Our approach offers a solution, especially for organizations struggling with fragmented systems and multiple vendors. We deliver AI-driven solutions built from proven standard building blocks—not costly custom work, but smart combinations that are precisely tailored to your situation. Everything under one roof, from implementation to management and support.
Specifically, we help you with:
- Transparent AI Architecture: Our systems are designed to ensure that human oversight is always maintained, a requirement for deployers under the AI Act.
- Agentic AI for Customer Service: What used to be called RPA, we now refer to as Agentic AI: self-thinking assistants that not only follow instructions but also take the initiative and act independently, with full logging and audit trails for compliance.
- Omnichannel overview without silos: A single central platform for phone calls, chat, WhatsApp, and email, so you can always track which AI is active on which channel.
- Documentation and governance support: We help you set up an AI registry and establish the appropriate processes to meet Article 26 obligations.
- ISO 27001-certified security: Our solutions comply with ISO 27001 (information security), ISO 9001, and ISO 26000, laying the foundation for a solid compliance record.
Would you like to know how your customer service is doing and what steps are needed to comply with the AI Act? Contact us, and we’ll work with you to determine the best approach for your organization.
Frequently Asked Questions
Does the AI Act also apply to small and medium-sized customer service organizations, or only to large companies?
Yes, in principle, the AI Act applies to all organizations that use AI systems in the EU, regardless of their size. However, small and medium-sized enterprises (SMEs) are subject to certain exemptions: for example, there are simplified procedures for conformity assessments, and regulators may take SMEs’ more limited resources into account when enforcing the law. Nevertheless, the core obligations—such as the transparency requirement for chatbots and the AI literacy requirement for employees—apply to everyone. So, even as an SME, start by conducting a basic inventory of your AI systems.
What should I do specifically if my AI supplier cannot yet provide a statement of conformity?
If your supplier cannot yet provide a declaration of conformity or technical documentation, this poses a serious risk—especially for high-risk systems. Put your request in writing and ask for a concrete roadmap toward compliance by August 2, 2026. If the supplier does not provide a clear answer, consider exploring alternatives or temporarily limiting the use of the system in question to functions that fall outside the high-risk category. In any case, document your own due diligence efforts, because as a deployer, you are jointly responsible for the use of non-compliant systems.
How can I explain an AI decision to customers in a practical way (Article 86) without using technical jargon?
Article 86 requires a clear explanation of the factors behind an AI decision, not a technical explanation of the model. Set up a simple process where an employee can use the available logs to explain what information the system used—for example: ‘Your request was forwarded to our specialists based on the type of product and your previous contact history.’ Ensure that your customer service representatives are trained to answer these types of questions and that the necessary information can be quickly retrieved from the system. Integrate this process into your existing complaints and appeals procedure.
My organization uses a chatbot from a third party that we did not develop ourselves. Am I still responsible for AI Act compliance?
Yes, as the deployer—the organization that actually uses the AI system for customer interactions—you have your own obligations under the AI Act, even if you didn’t develop the system yourself. Your responsibilities include, among other things: using the system in accordance with the provider’s instructions, establishing human oversight, retaining logs, and informing employees. The provider is responsible for the technical compliance of the system itself; you are responsible for how and for what purpose you use it. It is therefore essential to establish clear contractual agreements with your supplier regarding their compliance obligations.
How can I efficiently combine the AI Act obligations with my existing GDPR processes?
There is significant overlap between the AI Act and the GDPR, which you can leverage to avoid duplicating efforts. For example, you can expand the mandatory DPIA (Data Protection Impact Assessment) required by the GDPR to include an AI risk assessment, and supplement your existing processing register to create a combined AI and processing register. The AI Act’s logging requirements also align with the accountability obligations under the GDPR. So be sure to actively involve your privacy officer or DPO in your AI Act compliance process—they’re already familiar with the processes and can help develop an integrated approach that covers both sets of regulations.
What are the most common mistakes made when implementing AI Act compliance in customer service?
The most common mistake is underestimating the scope: organizations overlook AI functionalities that are ‘hidden’ within existing CRM or routing systems and focus solely on visible chatbots. A second common mistake is shifting all responsibility onto the vendor, even though deployers have their own obligations. We also see that the AI literacy requirement (Article 4)—which has been in effect since February 2025—is often overlooked: employees must demonstrate basic knowledge of the systems they work with. So start broad: take inventory of all systems, including the less obvious ones.
How do I keep my AI Act compliance up to date as the law continues to be rolled out?
The AI Act is a living regulation with a phased implementation schedule through 2027 and additional delegated acts that are yet to be published. Appoint an internal point person—such as an AI coordinator or compliance officer—to track regulatory developments and keep the AI register up to date. Subscribe to updates from the European AI Office and the Dutch regulator, and schedule an annual review of your AI register and risk assessments. Also ensure that new AI systems or functionalities undergo a compliance check as a standard procedure before being put into use, so that compliance is structurally ensured rather than reactive.


