What does the AI Act mean for omnichannel customer service?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

The AI Act has direct implications for omnichannel customer service: anyone who uses AI for customer interactions via phone, chat, email, or WhatsApp falls under the regulation and must comply with transparency requirements—and, in some cases, more stringent compliance requirements. The law will take effect in phases and imposes obligations on both providers of AI systems and the organizations that use these systems on a daily basis. Below, we answer the most frequently asked questions about what the AI Act specifically means for your customer service organization.

Which AI applications in customer service are covered by the AI Act?

Most AI applications in customer service fall into the “limited risk” or “minimal risk” category, which means they are subject to relatively light regulatory obligations. Examples include chatbots, virtual assistants, and automated email processing. However, as soon as an application profiles customers, evaluates them, or makes decisions that affect their access to services, you move into the high-risk category.

Specifically, these are the most common AI applications in omnichannel customer service and how they are categorized:

  • Chatbots and virtual assistants: Limited risk. Transparency requirements apply: Customers must be informed that they are communicating with an AI.
  • Automatic call routing based on customer profile: Potentially high risk if the system performs profiling or influences access to services.
  • Sentiment Analysis and Emotion Recognition: Please note: Emotion recognition in the workplace is prohibited under Article 5, unless a medical or safety exception applies.
  • AI-driven employee quality monitoring: Falls under employment and human resources management (Annex III), which classifies it as high-risk.
  • Automated response suggestions for agents: Generally low risk, provided that the agent makes the final decision.

The key question is always: Does the system make decisions that significantly affect the customer or employee, or does it merely support a human decision? When in doubt, it is wise to seek legal advice and document the system.

What are the requirements for high-risk AI in customer interactions?

If an AI system used in customer interactions is classified as high-risk, extensive obligations apply. The most stringent requirements fall on the system provider, but you, as the deployer (the organization implementing the system), also have specific responsibilities.

Requirements for Providers of High-Risk AI

Suppliers must establish an ongoing risk management system, maintain technical documentation, enable automatic event logging, and design the system in such a way as to ensure effective human oversight. In addition, a conformity assessment, CE marking, and registration in the EU database are mandatory.

Requirements for Deployers (Customer Service Organizations)

If you use a high-risk AI system in your customer service operations, you are considered a deployer and are subject to the following obligations:

  • Use the system in accordance with the provider’s instructions for use.
  • Assign human supervision to qualified and trained employees.
  • Keep logs for at least six months.
  • Inform employees before the equipment is put into service (Article 26(7)).
  • Where applicable, conduct a data protection impact assessment (DPIA).

Customers who are subject to a decision made by a high-risk system may, pursuant to Article 86, request an explanation of the determining factors. This has direct implications for how you structure your customer communications and appeal procedures.

When will the AI Act take effect for customer service organizations?

The AI Act is being implemented in phases, and the most relevant deadlines for customer service organizations in 2026 are either already in effect or just around the corner. As of February 2, 2025, the prohibitions in Article 5 and the AI literacy requirement will already be in effect. This means that prohibited applications, such as manipulative AI or emotion recognition in the workplace, are already not allowed.

The timeline that is most relevant for customer service:

  1. February 2, 2025 (already in effect): Prohibited Practices (Article 5) and AI Literacy Requirement (Article 4). Ensure that your employees have a basic understanding of the AI systems they work with.
  2. August 2, 2025 (already in effect): Requirements for large language models and penalty provisions are in effect. Do you use large language models in your customer service? If so, transparency requirements already apply.
  3. August 2, 2026 (upcoming deadline): Most requirements for high-risk Annex III systems will become enforceable. This is the most critical deadline for many customer service organizations.
  4. August 2, 2027: Additional requirements for high-risk AI used as a safety component in regulated products.

Practical advice: Start keeping a record of all the AI systems you use right away, determine your role for each system (provider, deployer, importer, or distributor), and verify that the provider of your systems is complying with its obligations.

What are the consequences of noncompliance with the AI Act?

The fines for noncompliance with the AI Act are substantial and will take effect on August 2, 2025. The amount depends on the severity of the violation and is calculated based on global annual revenue or a fixed amount, whichever is higher.

The three levels of sanctions:

  • Violations of prohibited practices (Article 5): Up to 35 million euros or 7% of global annual revenue.
  • Non-compliance with other obligations: Up to 15 million euros or 3% of annual revenue.
  • Inaccurate or misleading information provided to authorities: Up to 7.5 million euros or 1% of annual revenue.

In addition to financial risks, there are also operational and reputational risks. If a customer requests an explanation of an AI decision under Article 86 and you are unable to provide it, this could lead to complaints filed with regulators. In January 2026, Finland became the first EU member state to grant enforcement powers to its national authority, indicating that enforcement is rapidly approaching.

How do you prepare an omnichannel customer service operation for AI Act compliance?

Preparing an omnichannel customer service operation for AI Act compliance requires a structured approach: first, identify which AI systems you use, determine the risk category for each system, and then establish the corresponding governance framework. Start with the most urgent requirements that are already in effect.

A practical step-by-step guide:

  1. Create an AI registry: Document all the AI systems you use in your customer service operations, from chatbots to routing software and quality monitoring.
  2. Determine your role for each system: Are you a provider, deployer, importer, or distributor? Your obligations vary depending on your role.
  3. Classify the risk: Is the system high-risk (e.g., profiling or decisions regarding access to services)? Or does it fall under the category of limited risk with transparency requirements?
  4. Check your suppliers: Ask AI system providers for declarations of conformity and technical documentation. Are they CE-marked for high-risk systems?
  5. Train your employees: The AI literacy requirement (Article 4) is already in effect. Make sure employees understand how the AI systems they use every day work.
  6. Establish human oversight: For each high-risk system, designate a qualified person to monitor it and maintain logs.
  7. Integrate AI Act compliance into your GDPR processes: Many requirements overlap, such as the DPIA requirement and logging.

Organizations that are already working with fragmented systems from multiple vendors face an additional risk: it is difficult to ensure compliance if you do not have a centralized overview of which AI functionality is active in which channel.

What does the AI Act mean for customers who contact us through multiple channels?

For customers who contact us through multiple channels, the AI Act provides a number of specific rights and protections. The law strengthens the customer’s position vis-à-vis automated systems, particularly when AI decisions affect the services they receive.

The most relevant consumer rights in an omnichannel context:

  • Right to an Explanation: Customers who are subject to a decision made by a high-risk AI system (such as automated prioritization or referral) may, pursuant to Article 86, request an explanation of the determining factors.
  • Transparency Regarding the Use of AI: When a customer communicates with an AI system via chat or phone, it must be clear that the system is not a human. This requirement already applies under the transparency obligations for low-risk AI.
  • Protection against manipulation: AI systems may not use subliminal or manipulative techniques to influence customer behavior. This prohibition has been in effect since February 2, 2025.
  • Protection of Vulnerable Groups: AI must not exploit vulnerabilities based on age, disability, or socioeconomic status. This is relevant for customer service in sectors such as healthcare, government, and housing authorities.

For organizations with an omnichannel approach, this means you must check for each channel which AI is active and which transparency requirements apply. A customer who starts on WhatsApp, switches to the phone, and then receives an email must be provided with the correct information at every touchpoint regarding whether and how AI is being used.

How Pegamento Helps Ensure AI Act Compliance in Omnichannel Customer Service

We understand that AI Act compliance presents an additional challenge for many customer service organizations on top of their day-to-day operations. Our approach offers a solution, especially for organizations struggling with fragmented systems and multiple vendors. We deliver AI-driven solutions built from proven standard building blocks—not costly custom work, but smart combinations that are precisely tailored to your situation. Everything under one roof, from implementation to management and support.

Specifically, we help you with:

  • Transparent AI Architecture: Our systems are designed to ensure that human oversight is always maintained, a requirement for deployers under the AI Act.
  • Agentic AI for Customer Service: What used to be called RPA, we now refer to as Agentic AI: self-thinking assistants that not only follow instructions but also take the initiative and act independently, with full logging and audit trails for compliance.
  • Omnichannel overview without silos: A single central platform for phone calls, chat, WhatsApp, and email, so you can always track which AI is active on which channel.
  • Documentation and governance support: We help you set up an AI registry and establish the appropriate processes to meet Article 26 obligations.
  • ISO 27001-certified security: Our solutions comply with ISO 27001 (information security), ISO 9001, and ISO 26000, laying the foundation for a solid compliance record.

Would you like to know how your customer service is doing and what steps are needed to comply with the AI Act? Contact us, and we’ll work with you to determine the best approach for your organization.

Frequently Asked Questions

Geldt de AI Act ook voor kleine en middelgrote klantenservice-organisaties, of alleen voor grote bedrijven?

Ja, de AI Act geldt in principe voor alle organisaties die AI-systemen inzetten in de EU, ongeacht hun omvang. Voor kleine en middelgrote ondernemingen (kmo’s) gelden wel enkele verlichtingen: zo zijn er vereenvoudigde procedures voor conformiteitsbeoordelingen en mogen toezichthouders rekening houden met de beperktere middelen van kmo’s bij handhaving. Toch zijn de kernverplichtingen — zoals de transparantieplicht voor chatbots en de AI-geletterdheidsplicht voor medewerkers — voor iedereen van toepassing. Begin dus ook als kmo met een basisinventarisatie van je AI-systemen.

Wat moet ik concreet doen als mijn AI-leverancier nog geen conformiteitsverklaring kan aanleveren?

Als je leverancier nog geen conformiteitsverklaring of technische documentatie kan aanleveren, is dat een serieus risico — zeker voor hoog-risico systemen. Zet de vraag formeel op schrift en vraag om een concrete roadmap richting compliance vóór 2 augustus 2026. Als de leverancier geen duidelijk antwoord geeft, overweeg dan alternatieven te verkennen of het gebruik van het betreffende systeem tijdelijk te beperken tot functies die buiten de hoog-risico-categorie vallen. Documenteer in elk geval je eigen due diligence-inspanningen, want als deployer ben je mede verantwoordelijk voor het gebruik van niet-conforme systemen.

Hoe geef ik klanten op een praktische manier uitleg over een AI-beslissing (Artikel 86) zonder technische jargon?

Artikel 86 vereist een begrijpelijke uitleg van de bepalende factoren achter een AI-beslissing, niet een technische uiteenzetting van het model. Richt een eenvoudig proces in waarbij een medewerker aan de hand van de beschikbare logs kan uitleggen welke informatie het systeem heeft gebruikt — bijvoorbeeld: ‘Uw aanvraag is doorgestuurd naar onze specialisten op basis van het type product en uw eerdere contacthistorie.’ Zorg dat je klantenservicemedewerkers getraind zijn om dit soort vragen te beantwoorden en dat de benodigde informatie uit het systeem snel opvraagbaar is. Koppel dit proces aan je bestaande klachten- en bezwaarprocedure.

Mijn organisatie gebruikt een chatbot van een externe partij die wij zelf niet hebben gebouwd. Ben ik dan toch verantwoordelijk voor AI Act-naleving?

Ja, als deployer — de organisatie die het AI-systeem daadwerkelijk inzet voor klantinteracties — heb je eigen verplichtingen onder de AI Act, ook al heb je het systeem niet zelf ontwikkeld. Jouw verantwoordelijkheden omvatten onder meer: het systeem gebruiken conform de gebruiksaanwijzing van de aanbieder, menselijk toezicht inrichten, logs bewaren en medewerkers informeren. De aanbieder is verantwoordelijk voor de technische conformiteit van het systeem zelf; jij bent verantwoordelijk voor hoe en waarvoor je het inzet. Het is dus essentieel om goede contractuele afspraken te maken met je leverancier over hun compliance-verplichtingen.

Hoe combineer ik de AI Act-verplichtingen efficiënt met mijn bestaande AVG/GDPR-processen?

Er is veel overlap tussen de AI Act en de AVG, wat je kunt benutten om dubbel werk te voorkomen. Zo kun je de verplichte DPIA (gegevensbeschermingseffectbeoordeling) uit de AVG uitbreiden met een AI-risicobeoordeling, en je bestaande verwerkingsregister aanvullen tot een gecombineerd AI- en verwerkingsregister. De loggingvereisten van de AI Act sluiten ook aan op de verantwoordingsplicht onder de AVG. Betrek je privacy officer of DPO dus actief bij je AI Act-compliance traject — zij kennen de processen al en kunnen helpen om een geïntegreerde aanpak te ontwikkelen die beide regelgevingen afdekt.

Wat zijn de meest gemaakte fouten bij het implementeren van AI Act-compliance in klantenservice?

De meest voorkomende fout is het onderschatten van de scope: organisaties vergeten AI-functionaliteiten die ‘verborgen’ zitten in bestaande CRM- of routeringssystemen en focussen alleen op zichtbare chatbots. Een tweede veelgemaakte fout is het volledig afschuiven van verantwoordelijkheid op de leverancier, terwijl deployers eigen verplichtingen hebben. Verder zien we dat de AI-geletterdheidsplicht (Artikel 4) — die al geldt sinds februari 2025 — vaak wordt vergeten: medewerkers moeten aantoonbaar basiskennis hebben van de systemen waarmee ze werken. Begin dus breed: inventariseer alle systemen, ook de minder voor de hand liggende.

Hoe houd ik mijn AI Act-compliance up-to-date nu de wet nog verder uitgerold wordt?

De AI Act is een levende verordening met een gefaseerde inwerkingtreding tot 2027 en aanvullende gedelegeerde handelingen die nog worden gepubliceerd. Wijs intern een verantwoordelijke aan — bijvoorbeeld een AI-coördinator of compliance officer — die regelgeving bijhoudt en het AI-register actueel houdt. Abonneer je op updates van de Europese AI Office en de Nederlandse toezichthouder, en plan jaarlijks een herziening van je AI-register en risicobeoordelingen. Zorg ook dat nieuwe AI-systemen of -functionaliteiten standaard door een compliance-check gaan vóór ingebruikname, zodat naleving structureel geborgd is en niet reactief.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.