To inform customers about automated decision-making in accordance with the AI Act, you must communicate transparently about the use of AI, explain the logic behind decisions, and inform those affected of their rights. This applies to organizations that use AI systems that have legal consequences or significantly affect people in a similar manner. In this article, we answer the most frequently asked questions about AI-driven decision-making and the associated communication obligations.
What obligations does the AI Act impose regarding automated decision-making?
The AI Act imposes transparency requirements on organizations that use high-risk AI systems for automated decision-making. Specifically, this means that you must inform data subjects about the use of AI, document how the system works, and ensure human oversight. The extent of these obligations depends on the system’s risk category.
The AI Act uses four risk levels. Most applications fall into the “minimal risk” category and are largely unregulated. Systems with “limited risk,” such as chatbots, are subject to less stringent transparency requirements. High-risk AI is strictly regulated, and prohibited applications are not permitted effective immediately.
The high-risk category is most relevant to automated decision-making. Examples include systems used for credit assessments, employee selection, access to essential services, or admission to educational institutions. These applications are subject to requirements such as:
- Prepare and keep technical documentation up to date
- Implementing and maintaining a risk management system
- Making Human Oversight Technically Feasible
- Informing Data Subjects About the Use of the AI System
- Registration in the EU database for high-risk systems
Most of the requirements for high-risk Annex III systems will take effect on August 2, 2026. Organizations that are already using such systems would be wise not to delay their preparations any longer.
Who should be informed about automated decisions?
In the case of automated decision-making, you must first inform the natural persons who are being assessed by the system or whose behavior is being predicted. These are the individuals directly affected: customers, job applicants, insured individuals, or citizens who are the subject of the AI decision. In addition, there are information requirements for regulators and, in certain cases, downstream providers.
In the context of customer contact, this specifically refers to people who reach out to your organization, where an automated system determines how their request is handled, what priority it is given, or what offer they receive. They need to know that an AI system is involved in the decision that affects them.
For GPAI models—such as large language models that are integrated into customer contact systems—the model provider must also inform downstream parties about the model’s capabilities and limitations. If your organization uses such a model, you, as the deployer, are responsible for communicating with end users.
What must a notice regarding automated decision-making include?
A notice regarding automated decision-making must, at a minimum, state that an AI system is being used, the purpose of that system, the logic or criteria guiding the decision, and the rights of the data subject. The information must be understandable to the average reader, not just to technical experts or lawyers.
Specifically, a complete notification includes the following elements:
- System Identification: What type of AI system is being used, and for what purpose?
- Decision Logic: Which Factors or Data Influence the Outcome?
- Consequences: What is the legal consequence or the substantive impact on the person concerned?
- Rights of the data subject: right to an explanation, right to human intervention, right to object
- Contact Information: How the data subject can reach a person with questions or objections
For high-risk systems, the AI Act stipulates that the information must be available before the system makes a decision that affects the data subject. Providing information after the fact is insufficient in most cases.
How does the AI Act differ from the GDPR with regard to automated decisions?
The AI Act and the GDPR overlap in the area of automated decision-making, but they complement rather than replace each other. The GDPR grants data subjects the right not to be subject solely to automated decision-making with legal effects and establishes the right to a subsequent explanation. The AI Act imposes additional requirements on the development, documentation, and oversight of AI systems themselves, even before a decision is made.
What does the GDPR cover?
The GDPR (Article 22) generally prohibits fully automated decision-making with legal effects, unless an exception applies, such as explicit consent or a contractual necessity. The data subject has the right to human intervention, the right to express their point of view, and the right to challenge the decision. The GDPR focuses on the rights of the individual after the decision has been made.
What does the AI Act add?
The AI Act goes a step further by imposing requirements on the system itself, even before it is deployed. These include mandatory risk assessments, technical documentation, accuracy tests, and the incorporation of human oversight as a technical requirement. Whereas the GDPR provides protection through rights, the AI Act provides protection through system quality and transparency at the outset. Organizations must comply with both frameworks; compliance with the GDPR is not a substitute for compliance with the AI Act.
How do you draft a clear customer notice about AI decisions?
Write a clear customer notice about AI decisions in plain language, from the customer’s perspective. Avoid legal jargon and technical terms. Start with what the customer notices right away, explain why AI is being used, and make it clear what the customer can do if they disagree. Concrete and honest language builds more trust than formal disclaimers.
Practical guidelines for effective customer communication:
- Use active voice: write “We use an automated system to…” instead of “An automated system is used to…”
- Specify the goal in concrete terms: state what the system will be used for, such as prioritizing customer inquiries or evaluating an application
- Avoid vague descriptions: “algorithm” without an explanation means nothing to a customer; describe what the system actually does
- Explain rights in plain language: “You can always ask for a staff member to review your situation.”
- Make it easy to find: ensure that the information is available when the customer needs it, not just in the terms and conditions
Test the message with a small group of customers or employees who do not have a technical background. If they understand the text, you are likely complying with the spirit of the transparency requirement.
What are the consequences of non-compliance with the AI Act for customer communications?
Non-compliance with the AI Act regarding customer communication can result in significant fines, reputational damage, and mandatory changes to your systems. The fine structure has three tiers: violations of prohibited practices can result in fines of up to 35 million euros or 7% of global annual revenue; non-compliance with other obligations can result in fines of up to 15 million euros or 3%; and providing incorrect information to authorities can result in fines of up to 7.5 million euros or 1%.
In addition to financial risks, there are also operational consequences. Regulators may require you to temporarily shut down or modify a system before you are allowed to put it back into use. In January 2026, Finland became the first member state to formally grant enforcement powers to its national authority. Other EU member states are following suit, which means that enforcement is becoming increasingly concrete and imminent.
For small and medium-sized organizations, the fine is capped at the lower of a fixed amount or a percentage of revenue. This offers some protection, but it does not exempt you from the obligation to comply. Proactively investing in proper customer communication is significantly less expensive than having to make corrections later under pressure from a regulatory authority.
How Pegamento Helps with Automated Decision-Making and AI Act Compliance
If you’re using AI in your customer interactions, you want to be sure that your systems are transparent, traceable, and compliant. We help organizations use AI responsibly in customer service, where compliance isn’t an afterthought but an integral part of the solution. Our approach combines smart technology with clear governance—without costly customization, but with proven modules that you can deploy quickly.
Specifically, we offer:
- Agentic AI assistants that take the initiative and act independently, but with human oversight always built in
- Omnichannel customer engagement solutions that manage all channels under one roof, including audit trails for automated decisions
- Support in drafting clear customer communications and internal documentation in accordance with the AI Act requirements
- Everything under one roof: from implementation to management, so you have a single point of contact and avoid a complex supplier structure
Pegamento is ISO 27001 certified for information security, supplemented by ISO 9001 and ISO 26000, which means you can rely on a partner that takes quality and responsibility seriously. Would you like to know how your organization can prepare for the AI Act requirements? Contact us, and we’d be happy to help you figure it out.
Frequently Asked Questions
Does the AI Act also apply to small businesses that use only one AI tool in their customer interactions?
Yes, the AI Act applies to all organizations that use AI systems within the EU, regardless of their size. However, the law does offer some protection for smaller organizations: fines are capped at the lower of a fixed amount or a percentage of revenue. Still, as a small business, you are not exempt from the transparency and documentation requirements if you use a high-risk system. A first step is to determine which risk category your AI application falls into.
How do I know if the AI system I’m using is classified as ‘high-risk’?
An AI system falls into the high-risk category if it is used for applications listed in Annex III of the AI Act, such as credit scoring, employee selection, access to essential services, or educational admissions. If your system makes decisions that have legal consequences or affect people in a similarly significant way, there’s a good chance it’s high-risk. If in doubt, consult the official EU checklist or seek legal or technical advice to confirm the classification.
What is the most common mistake made when drafting a customer notice about AI decisions?
The most common mistake is burying the AI notice in the terms and conditions or a privacy statement that customers rarely read. The AI Act requires that information be available at the time it is relevant to the data subject—that is, before or at the time the decision is made. A second common mistake is using vague terms such as ‘automated processing’ without specifically explaining what the system does and how it affects the customer.
Do we also have to comply with the AI Act if we purchase an AI tool from a third-party vendor?
Yes, as the deployer (the organization that deploys the AI system), you remain responsible for communicating with end users and for ensuring human oversight, even if the system was developed by a third-party provider. The provider is responsible for the technical documentation and the compliance of the system itself, but you are responsible for its proper deployment. When negotiating the contract, ensure that your supplier provides the necessary documentation and information you need to meet your own obligations.
How do I combine the obligations under the AI Act with existing GDPR obligations in practice?
The most practical approach is to use your existing GDPR documentation as a starting point and expand it to include the additional AI Act requirements. Where the GDPR already requires a privacy notice and a record of processing activities, add the AI-specific elements: risk assessments, technical documentation, and transparency information about the decision-making logic. Combine the information on data subjects’ rights into a single, easy-to-understand document so that customers aren’t overwhelmed with separate legal statements.
What exactly does ‘human oversight’ mean, and how do I implement it technically?
Human oversight means that an employee must always be able to understand, review, correct, or override an AI decision before it has a definitive impact on a data subject. Technically speaking, this means your system must include a ‘human-in-the-loop’ or ‘human-on-the-loop’ mechanism, depending on the risk category. In practice, this could be an approval step for high-impact decisions, a dashboard where employees can review AI recommendations, or an escalation path through which the customer can always reach a human employee.
By when must my organization be compliant with the AI Act requirements for high-risk systems?
Most requirements for high-risk Annex III systems take effect on August 2, 2026. That may seem far off, but the preparation time required for risk assessments, technical documentation, system modifications, and drafting customer communications is considerable. Organizations that are already working with high-risk AI are advised to start a gap analysis immediately to determine what adjustments are needed and how much time and resources will be required.


