What are the transparency requirements in the AI Act for customer service?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

The AI Act imposes specific AI transparency obligationson customer service organizations, depending on the risk level of the system you use. If your AI makes decisions about customers, assesses access to services, or performs profiling, you’ll likely fall into the high-risk category, which comes with corresponding documentation and reporting requirements. In this article, we answer the most frequently asked questions about what the AI Act specifically means for your customer service department.

Which customer service systems are covered by the AI Act?

Customer service systems fall under the AI Act if they use AI to support or make decisions that directly affect customers. Chatbots and virtual assistants that merely provide information are subject to less stringent transparency requirements. Systems that assess, profile, or determine customers’ access to services are classified as high-risk.

The AI Act distinguishes between four risk levels. For customer service, two levels are particularly relevant:

  • High-risk AI: systems that make decisions regarding access to essential services, assess creditworthiness, or perform customer profiling. Examples include automated scoring models for customer segmentation or systems that determine which offers are made to which customers.
  • Low-risk AI: chatbots, voicebots, and other AI systems that communicate directly with customers. There is a transparency requirement here: customers must know that they are talking to an AI system.

Systems that perform purely procedural or preparatory tasks and do not pose a significant risk to fundamental rights may fall outside the high-risk category. However, systems that profile customers are always considered high-risk, regardless of how limited that profiling may seem.

What exactly must a company report if it uses AI in customer interactions?

If you use AI in customer interactions, you must actively inform customers when they are communicating with an AI system. This applies to chatbots, voicebots, and other automated systems that engage directly with people. Customers must be informed of this before or at the start of the conversation.

If you use high-risk AI, your obligations go even further. As the deployer—the party that deploys the system under its own authority—you must:

  • Use the system in accordance with the provider’s instructions for use
  • Assign human supervision to qualified and trained individuals
  • Retain logs for at least six months
  • Informing employees before the system is put into use (Article 26(7))
  • Conduct a data protection impact assessment (DPIA) where applicable

Customers who are subject to a decision made by a high-risk system have the right, under Article 86, to request an explanation of the factors that determined that decision. So if you use an AI system that determines whether a customer is eligible for a service or offer, you must be able to provide that explanation.

Does the AI Act also apply to AI systems from third-party vendors?

Yes, the AI Act applies even if you use AI systems from third-party providers. As an organization that uses the system under its own authority, you are a deployer with your own obligations. You cannot place the entire responsibility on the provider.

In addition, there is an important point to keep in mind: you can become a provider yourself without even realizing it. This happens when you:

  • Put your own name or brand on an AI system
  • Makes a substantial change to the system
  • Adjusts the intended purpose in such a way that the system becomes high-risk

In such cases, you assume all of the provider’s obligations, including technical documentation, conformity assessment, and CE marking. It is therefore advisable, when purchasing AI tools for customer service, to specify in the contract who is responsible for what and to verify that the provider has the appropriate documentation and declarations of conformity.

What are the consequences of failing to meet the transparency requirements?

Failure to comply with the transparency requirements of the AI Act can result in substantial fines. Noncompliance with the general obligations, including transparency, may be punishable by a fine of up to 15 million euros or 3% of global annual revenue, whichever is higher.

The penalty structure has three levels:

  • Violations of prohibited practices: up to 35 million euros or 7% of global annual revenue
  • Non-compliance with other obligations: up to 15 million euros or 3%
  • Inaccurate or misleading information provided to authorities: up to 7.5 million euros or 1%

For smaller organizations, the lower of the percentage or the fixed maximum amount always applies. Most obligations for high-risk systems will become enforceable as of August 2, 2026. However, the transparency requirement for chatbots and the prohibited practices have been in effect since February 2, 2025. Supervision and enforcement are the responsibility of national market surveillance authorities, which may mean that priorities differ by Member State.

How does the AI Act differ from the GDPR for customer service organizations?

The AI Act and the GDPR complement each other, but address different risks. The GDPR protects personal data and governs how it may be processed. The AI Act regulates the behavior and operation of AI systems themselves, regardless of whether personal data is involved.

In practice, they overlap in several ways:

  • Both require a DPIA for high-risk processing operations or high-risk AI systems
  • Both give those affected the right to an explanation of automated decisions
  • Both set requirements for the quality and representativeness of data

The difference lies in the focus. The GDPR asks: What data do you process, and on what legal basis? The AI Act asks: How does the system work, what risks does it pose, and is there sufficient human oversight? For customer service organizations, this means you must consider both frameworks side by side. A chatbot that processes customer data is subject to the GDPR for data processing and to the AI Act for the transparency requirement toward the customer.

What steps can a customer service department take right now?

A customer service department can already take concrete steps to become AI Act-compliant, even though most high-risk obligations will not be fully enforceable until August 2026. This is because the transparency requirement for chatbots and virtual assistants is already in effect.

Practical steps you can take right away:

  1. Create an AI registry: identify which AI systems you use in customer interactions, what they do, and what role you play in them (deployer, provider, or distributor).
  2. Monitor customer communications: Ensure that customers always know when they are interacting with an AI system by displaying a clear notification at the start of a chat or phone call.
  3. Assess the risk level: determine for each system whether it is high-risk, particularly if it performs profiling or makes decisions regarding access to services.
  4. Review supplier contracts: specify who is responsible for what, and ask suppliers to provide documentation regarding compliance.
  5. Train employees: The AI literacy requirement (Article 4) is already in effect. Ensure that employees who work with AI systems understand what those systems do and what their limitations are.
  6. Retain logs: Establish processes to retain interaction logs for at least six months for high-risk systems.

The sooner you start, the less you’ll have to adjust later. The compliance requirements for high-risk Annex III systems will become enforceable as of August 2, 2026, but preparation takes time.

How Pegamento Helps with AI Compliance in Customer Service

Compliance with the AI Act requires a clear understanding of which systems you use, how they work, and the responsibilities associated with them. We help customer service organizations deploy AI in a responsible and transparent manner, without getting bogged down in complex supplier management or an unclear division of responsibilities.

What we offer specifically:

  • Streamlined AI solutions for customer service that build transparency with customers right in from the start
  • Agentic AI assistants that not only follow instructions but also take the initiative on their own—an evolution from executive RPA bots to self-thinking assistants that we position as Agentic AI
  • Everything under one roof: from implementation to management and support, so you have a single point of contact and no silos between systems and vendors
  • Customized solutions using standard building blocks, so you can scale quickly without costly customization
  • Support in setting up human oversight and logging, in accordance with the requirements of the AI Act
  • ISO 27001-certified information security as a foundation, supplemented by ISO 9001 and ISO 26000

Would you like to know how your customer service department is currently performing and what steps are needed to become compliant? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Hoe weet ik of mijn chatbot als 'hoog-risico' wordt geclassificeerd onder de AI Act?

Een chatbot is hoog-risico als hij niet alleen informatie geeft, maar ook beslissingen ondersteunt of neemt die klanten direct raken, zoals het bepalen van toegang tot diensten, het uitvoeren van profilering of het beoordelen van kredietwaardigheid. Een eenvoudige FAQ-bot die vragen beantwoordt, valt doorgaans onder de lichtere transparantieverplichtingen. Twijfel je over de classificatie van jouw systeem? Laat dan een risicoanalyse uitvoeren door een specialist, want een verkeerde inschatting kan leiden tot het mislopen van verplichte documentatie en toezichtmaatregelen.

Wat is de minimale manier om te voldoen aan de transparantieverplichting voor chatbots die al geldt vanaf februari 2025?

De minimale vereiste is dat klanten duidelijk en tijdig worden geïnformeerd dat ze met een AI-systeem communiceren, en dit moet gebeuren vóór of op het moment dat het gesprek begint. In de praktijk betekent dit een korte, begrijpelijke melding aan het begin van een chatgesprek of telefonische interactie, zoals: ‘U spreekt met een virtuele assistent.’ Let op: de melding moet oprecht en ondubbelzinnig zijn — een verborgen vermelding in de algemene voorwaarden is niet voldoende.

Wat moet ik doen als een klant vraagt om uitleg over een beslissing die door een AI-systeem is genomen?

Op grond van Artikel 86 van de AI Act heeft een klant het recht om een uitleg te vragen over de bepalende factoren achter een beslissing van een hoog-risico AI-systeem. Je moet in staat zijn om in begrijpelijke taal toe te lichten welke factoren de beslissing hebben beïnvloed, zonder dat je daarvoor de volledige technische werking van het model hoeft bloot te leggen. Zorg er daarom voor dat je bij de leverancier of interne beheerder toegang hebt tot voldoende informatie over de beslissingslogica, en train medewerkers in het geven van deze uitleg.

Hoe leg ik contractueel de verantwoordelijkheden vast met mijn AI-leverancier?

Zorg ervoor dat in het contract met je leverancier expliciet is vastgelegd wie de aanbieder is en wie de deployer, en welke verplichtingen bij welke partij liggen. Vraag de leverancier om technische documentatie, conformiteitsverklaringen en informatie over hoe het systeem getraind is en hoe het werkt. Voeg ook afspraken toe over wat er gebeurt bij een substantiële wijziging van het systeem, want dat kan betekenen dat jij onverwacht de aanbiedersrol overneemt met alle bijbehorende verplichtingen.

Geldt de AI-geletterdheidsplicht ook voor medewerkers die AI-tools alleen indirect gebruiken?

Artikel 4 van de AI Act verplicht organisaties om te zorgen dat medewerkers die met AI-systemen werken een voldoende niveau van AI-geletterdheid hebben, afgestemd op hun rol en de risico’s van het systeem. Dit geldt in de eerste plaats voor medewerkers die direct met AI-systemen werken of toezicht houden op geautomatiseerde beslissingen. Voor medewerkers die AI alleen indirect raken, is een basisniveau van begrip wenselijk maar minder strikt vereist — het is echter verstandig om ook hen te informeren over wat de systemen doen en waar de grenzen liggen.

Wat zijn de meest voorkomende fouten die klantenservice-organisaties maken bij het implementeren van AI Act-compliance?

Een veelgemaakte fout is aannemen dat de volledige verantwoordelijkheid bij de leverancier ligt, terwijl je als deployer altijd eigen verplichtingen houdt. Andere veelvoorkomende fouten zijn: geen AI-register bijhouden, de transparantiemelding te laat of te onduidelijk plaatsen, en vergeten dat de AI-geletterdheidsplicht en de transparantieverplichting voor chatbots al van kracht zijn. Organisaties wachten ook vaak te lang met voorbereiding op de hoog-risico verplichtingen van augustus 2026, terwijl een gedegen AI-register en risicoanalyse al maanden in beslag kunnen nemen.

Moet ik een nieuwe DPIA uitvoeren als ik al een DPIA heb gedaan in het kader van de AVG?

Niet per se, maar je bestaande DPIA dekt waarschijnlijk niet alle vereisten van de AI Act. De AVG-DPIA richt zich op risico’s voor persoonsgegevens, terwijl de AI Act ook vraagt om een beoordeling van de werking van het systeem, de kwaliteit van trainingsdata, en de aanwezigheid van menselijk toezicht. Het is raadzaam om je bestaande DPIA aan te vullen of een gecombineerde beoordeling uit te voeren die beide kaders dekt, zodat je geen overlap mist én geen gaten laat vallen.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.