How do you train contact center employees on the AI Act?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

To train contact center employees on the AI Act, you need to start with the AI literacy requirement that has been in effect since February 2, 2025. Every agent who works with AI systems must understand what those systems do, what risks they pose, and how human oversight works in practice. The training varies by role: agents, team leaders, and IT managers each have different obligations under the regulation. In this article, we answer the most frequently asked questions about AI Act training in a contact center, so you can get started right away. To learn more about how AI-driven technology is used responsibly, visit the page on AI-driven intelligence.

What does the AI Act require contact center employees to know?

The AI Act requires every employee who works with or makes decisions based on AI systems to have sufficient AI literacy. This means understanding what the system does, what its limitations are, how to recognize automation bias, and when human intervention is necessary. This requirement applies to deployers—that is, organizations that deploy AI—not just to developers.

The AI literacy requirement is set forth in Article 4 of the regulation and is already enforceable. This is not a non-binding recommendation, but a legal requirement. For contact centers, this specifically means that employees must know:

  • Which AI systems they use on a daily basis, for example, for call routing, quality monitoring, or customer profiling
  • What these systems can and cannot do, including their known limitations and margins of error
  • How they can follow, adjust, or ignore an AI-driven recommendation or decision
  • When they need to escalate a situation to a human colleague or supervisor
  • That customers may, pursuant to Article 86, request an explanation of decisions influenced by a high-risk AI system

In addition, Article 26(7) requires deployers to inform employees before a high-risk AI system is put into use. Training is therefore not something that can be organized after the fact, but a prerequisite for putting the system into use.

Which AI systems in a contact center are covered by the AI Act?

Not every AI system in a contact center is automatically subject to the strictest rules of the AI Act. The regulation distinguishes between four risk levels: prohibited applications, high-risk systems, systems with limited risk, and systems with minimal risk. Most contact center AI falls into the latter two categories, but there are exceptions that require immediate action.

Systems that are likely to be classified as high-risk

High-risk AI in a contact center applies when the system falls under one of the eight domains listed in Annex III. Of particular relevance to contact centers are: systems used to provide access to essential services such as lending, insurance, or emergency calls, and systems that perform customer profiling. Profiling of natural persons is always high-risk, regardless of the domain used. Examples include AI that automatically creates a customer profile based on conversation behavior and uses that profile for prioritization or offers.

Low-Risk Systems and What That Means

Chatbots and virtual assistants that interact with customers generally fall under the transparency requirements for low-risk AI. Customers must be informed that they are communicating with an AI system. This is a less stringent requirement than that for high-risk AI, but it is enforceable. Emotion recognition in the workplace—for example, systems that analyze the mood of employees or customers—is explicitly prohibited unless a medical or safety exception applies. This prohibition has been in effect since February 2, 2025.

How does AI Act training vary by role in the contact center?

AI Act training is not the same for everyone. The regulation imposes different obligations on different roles, and an effective training program is designed to reflect that. Broadly speaking, there are three levels: frontline employees, team leaders and supervisors, and IT or compliance officers.

Frontline employees

Employees who work with AI-powered tools on a daily basis need to understand how those tools affect their work. They don’t need to be technical experts, but they do need to know when it’s appropriate to ignore an AI recommendation, how to inform a customer about the use of AI, and how to initiate an escalation. The focus is on practical action and awareness of automation bias: the tendency to blindly follow AI outcomes without critical scrutiny.

Team Leaders and Supervisors

Team leaders are responsible for assigning human oversight to AI-driven processes. Article 26 of the AI Act requires that deployers assign human oversight to competent and trained individuals. Supervisors must therefore not only understand how the systems work, but also know how to organize oversight, identify anomalies, and report them. They are also the first point of contact if a customer requests an explanation of an AI-driven decision.

IT and Compliance

IT managers and compliance officers have the most extensive training needs. They must maintain the AI systems register, determine the organization’s role (provider, deployer, importer, or distributor), retain logs for at least six months, and conduct a data protection impact assessment where required. They must also know when a system change could inadvertently make the organization a provider, with all the associated obligations that entails.

How do you set up an AI Act training program for your team?

You can build an effective AI Act training program for a contact center in four steps: assess, classify, train by role, and document. Don’t start with the training itself; instead, begin by creating a comprehensive overview of all the AI systems you use and the role your organization plays in them.

  1. Establish an AI registry. Document which AI systems you use, what they do, which vendor provides them, and what risk level applies. This inventory serves as the foundation for everything that follows.
  2. Determine your role for each system. Are you a deployer, an importer, or did you develop the system yourself? The obligations vary significantly. Deployers have fewer obligations than providers, but they are still responsible for proper use and human oversight.
  3. Develop role-specific training modules. Use the three levels from the previous section: frontline, supervisors, and IT/compliance. Make sure the content aligns with the day-to-day realities of each group, and use specific examples from your own contact center environment.
  4. Document the training. Keep a record of who completed which training and when. This is not just an administrative formality, but proof of compliance. Also, keep the user manuals provided by AI vendors, as deployers are required to use the systems in accordance with those instructions.

Repeat the training whenever there is a significant system change or when new AI tools are deployed. The AI Act requires that employees be informed before high-risk systems are put into use, so training must be part of your implementation process, not a separate activity carried out afterward.

What do you need to document to demonstrate compliance with the AI Act?

To demonstrate compliance with the AI Act, contact center organizations must maintain a combination of records, logs, and training documentation. The regulation imposes specific retention requirements on deployers, and in the event of an audit or complaint, you want to be able to immediately demonstrate that you have met your obligations.

The minimum documentation you must keep includes:

  • AI Systems Registry: An overview of all AI systems in use, their risk level, vendor, and intended use
  • Supplier Instructions: Keep the instructions provided by suppliers and document that you are using your systems in accordance with those instructions
  • Logs of AI Decisions: For high-risk systems, there is a retention requirement of at least six months for automatically generated logs
  • Training Records: Who took which training course, on what date, and covering what content
  • Oversight Structure: Defining who is responsible for human oversight of which system
  • DPIA Documentation: Where a Data Protection Impact Assessment is required, it must be demonstrably conducted

Under Article 86, customers or affected parties may request an explanation of decisions influenced by a high-risk AI system. Make sure you are actually able to provide that explanation, which means you must be able to reconstruct the system’s determining factors.

What are the consequences if contact center employees do not comply with the AI Act?

If a contact center organization fails to comply with the AI Act, it risks substantial fines and reputational damage. The fine structure has three levels: violations of the prohibited practices under Article 5 can result in fines of up to 35 million euros or 7% of global annual revenue; non-compliance with other obligations can result in fines of up to 15 million euros or 3%; and providing incorrect information to regulators can result in fines of up to 7.5 million euros or 1%.

In addition to financial penalties, there are also operational consequences. If a regulator determines that you are using a high-risk system without demonstrable human oversight or without the required employee information, the use of that system may be suspended. For a contact center that relies on AI-supported routing, quality monitoring, or self-service, this can directly impact operations.

Enforcement for high-risk Annex III systems will become mandatory as of August 2, 2026. That may seem like it’s still some time away, but the AI literacy requirement and the prohibitions under Article 5 are already in effect. In January 2026, Finland became the first country to grant enforcement powers to its national authority. Other member states are expected to follow suit soon. Delaying compliance is therefore a risk that your organization consciously takes.

How Pegamento Helps Ensure AI Act Compliance in the Contact Center

If you use AI in your contact center, you—as the deployer—are responsible for its proper use, human oversight, and demonstrable compliance with the AI Act. This requires more than just one-time training: it calls for a structured approach in which technology, processes, and people are aligned. We provide concrete support in this area, drawing on our expertise in Agentic AI for customer service. Agentic AI represents the evolution from task-based automation to self-thinking assistants that not only follow instructions but also take the initiative and act independently—always within the parameters set by your organization.

What we can do for you:

  • Provide insight into which AI systems are in use in your contact center and what the associated risk level is
  • Provide role-specific training support for frontline employees, supervisors, and IT managers
  • Delivering AI solutions designed with human oversight as a starting point, not as an afterthought
  • Set up documentation and logging so that you can demonstrate compliance in the event of an audit or complaint
  • Get everything under one roof: from implementation to management and support, without complex supplier structures

We work with proven standard building blocks that we cleverly combine into a solution tailored to your organization and industry, without the need for costly custom development. Our approach is ISO 27001 certified (information security), supplemented by ISO 9001 and ISO 26000. Would you like to know where your contact center stands right now and what it will take to become AI Act-compliant? Get in touch, and we’d be happy to help you figure it out.

Frequently Asked Questions

Geldt de AI-geletterdheidsplicht ook voor medewerkers die AI-tools alleen indirect gebruiken, zoals via een dashboard of rapportage?

Ja, de verplichting geldt voor iedere medewerker die werkt met of beslissingen neemt op basis van AI-systemen, ook als dat indirect gebeurt. Als een teamleider stuurinformatie gebruikt die door een AI-systeem is gegenereerd, valt dat onder het bereik van Artikel 4. De training hoeft niet technisch van aard te zijn, maar de medewerker moet wel begrijpen dat de informatie AI-gegenereerd is, wat de beperkingen zijn en wanneer kritisch doorvragen of escaleren nodig is.

Wat als onze AI-leverancier zegt dat zijn systeem geen hoog-risico AI is? Mogen we daar als contactcenter op vertrouwen?

Nee, je kunt als deployer niet blind vertrouwen op de classificatie van een leverancier. De eindverantwoordelijkheid voor correct gebruik ligt bij jouw organisatie. Controleer zelf of het systeem valt onder een van de domeinen van Annex III, en let specifiek op klantprofilering en gebruik bij essentiële diensten. Leg je eigen beoordeling vast in je AI-register, inclusief de onderbouwing, zodat je bij een audit kunt aantonen dat je een zelfstandige afweging hebt gemaakt.

Hoe vaak moet AI Act-training worden herhaald, en is er een verplichte minimale frequentie?

De AI Act schrijft geen vaste herhalingsfrequentie voor, maar verplicht wel dat werknemers worden geïnformeerd vóór de ingebruikname van een hoog-risico systeem én bij significante wijzigingen. Praktisch betekent dit dat training een terugkerend onderdeel moet zijn van je HR- en implementatieprocessen, niet een eenmalige activiteit. Een jaarlijkse opfrissing gecombineerd met een verplicht trainingsmoment bij iedere nieuwe of gewijzigde AI-tool is een werkbare en aantoonbaar compliante aanpak.

Wat is automation bias precies, en hoe herken je het in de dagelijkse praktijk van een contactcenter?

Automation bias is de neiging van mensen om de uitkomst van een geautomatiseerd systeem klakkeloos te accepteren, ook als die uitkomst onjuist of onvolledig is. In een contactcenter uit zich dit bijvoorbeeld doordat een medewerker een AI-aanbeveling voor een klantoplossing overneemt zonder de context van het gesprek mee te wegen, of doordat een supervisor een kwaliteitsscore van een AI-monitoringsysteem niet ter discussie stelt. Training op dit thema richt zich op het actief aanmoedigen van kritisch denken: vraag jezelf bij elke AI-aanbeveling af of de uitkomst klopt met wat je zelf waarneemt.

Wat moeten we doen als een klant op basis van Artikel 86 uitleg vraagt over een AI-gestuurde beslissing?

Zorg dat je als organisatie vooraf een procedure hebt ingericht voor dit soort verzoeken, zodat medewerkers weten wie ze moeten inschakelen en welke informatie beschikbaar moet zijn. De uitleg moet inzicht geven in de bepalende factoren van de AI-beslissing, zoals welke gegevens zijn gebruikt en hoe zwaar die hebben meegewogen. Frontline medewerkers hoeven dit niet zelf te beantwoorden, maar moeten wel weten hoe ze het verzoek correct doorgeleiden naar de juiste persoon binnen de organisatie.

Wanneer wordt een contactcenterorganisatie ongemerkt aanbieder in plaats van deployer, en waarom maakt dat zo veel verschil?

Je wordt aanbieder zodra je een AI-systeem substantieel aanpast, bijvoorbeeld door het te hertrainen op eigen data, de beslislogica te wijzigen of het systeem te integreren op een manier die buiten de oorspronkelijke gebruiksbestemming van de leverancier valt. Het verschil is groot: aanbieders hebben aanzienlijk zwaardere verplichtingen dan deployers, waaronder conformiteitsbeoordelingen, technische documentatie en registratie in de EU-databank. Betrek je IT- en complianceteam bij elke significante aanpassing van een AI-systeem om te beoordelen of je van rol verandert.

Hoe pak je de AI Act-training aan in een contactcenter met veel verloop en wisselende medewerkers?

Bouw AI Act-training in als vast onderdeel van het onboardingprogramma voor nieuwe medewerkers, zodat compliance niet afhankelijk is van ad-hocmomenten. Gebruik korte, rolspecifieke modules die snel te doorlopen zijn en direct aansluiten op de tools die een medewerker in zijn of haar functie gebruikt. Zorg dat de trainingsregistratie automatisch wordt bijgehouden in je HR-systeem, zodat je bij een audit altijd actueel bewijs van compliance kunt overleggen, ongeacht het verloop.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.