What does the AI Act say about the use of chatbots in customer service?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

The EU AI Act imposes specific obligations on companies that use an AI chatbot in their customer service, but the extent of these obligations depends on the chatbot’s risk level. For most customer service chatbots, the primary requirements are transparency obligations: users must be aware that they are communicating with an AI. Below, we answer the most frequently asked questions about what the AI Act specifically means for your organization.

What obligations does the AI Act impose on companies that use chatbots?

The AI Act imposes at least a transparency requirement on companies that use an AI chatbot: users must always know that they are communicating with an AI system and not with a human. Depending on the chatbot’s risk level, additional, more stringent obligations may apply, such as risk management, technical documentation, and human oversight.

As a deployer—the party that deploys an AI system under its own responsibility—you are required to use the system as intended by the provider. Furthermore, you must assign human oversight to competent and trained employees, retain logs for at least six months, and inform your employees before the system is put into use. This is outlined in Article 26 of the regulation.

Important to know: If you modify an existing AI system so significantly that it is given a new purpose, or if you put your own name on the system, you legally become the provider yourself. This entails significantly more stringent obligations, such as preparing technical documentation, conducting a conformity assessment, and affixing a CE marking.

What risk level will customer service chatbots be assigned under the AI Act?

Most customer service chatbots fall under the “limited risk” category in the AI Act. This means they are not prohibited and do not have to meet the strict requirements for high-risk AI, but they are subject to less stringent transparency obligations. Only chatbots that make decisions regarding access to essential services, such as credit or insurance, are classified as high-risk.

The AI Act distinguishes four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (transparency requirements), and minimal risk (virtually unregulated). A standard chatbot that answers questions, refers customers, or provides information typically falls into the limited-risk category.

Please note: as soon as a chatbot performs profiling of individual customers, it is automatically considered high-risk. This also applies if the chatbot plays a role in decisions regarding access to services deemed essential, such as emergency calls or insurance. In such cases, all high-risk obligations apply, including a risk management system, technical documentation, and a conformity assessment.

What is the transparency requirement for chatbots, and how does it work in practice?

The transparency requirement means that you must clearly and promptly inform users that they are interacting with an AI system, not a human. This must be done at the start of the interaction, so that the user can make an informed decision about how to proceed. You may not hide this information in fine print or somewhere at the bottom of a page.

In practice, this means that your chatbot must explicitly state at the start of a conversation that it is an AI. A message such as “You are now chatting with our virtual assistant” or “This is an automated AI chatbot” meets the requirements. The message must be understandable to the average user, so avoid technical jargon.

There is one exception: if the user has specifically requested that an AI be used, or if its use is self-evident to the user, the requirement for explicit notification does not apply. In most customer service environments, however, that clarity is not self-evident, so an explicit notification is the safest approach.

Does the AI Act also apply to chatbots that are already in use?

Yes, the AI Act also applies to existing AI chatbots, but there is a transition period. Systems that were already on the market before August 2, 2025, do not have to be fully compliant until August 2, 2027, at the latest. However, the transparency requirement and the prohibited practices will take effect in August 2025 and February 2025, respectively.

This means you need to take action now, even if your chatbot has been up and running for years. The first step is to take stock of all AI systems within your organization and determine what role you play in them: are you a deployer, provider, importer, or distributor? Next, assess the risk level for each system and identify the resulting obligations.

Organizations would be wise to maintain an internal AI registry. In it, you document which systems you use, what their purpose is, who is responsible for oversight, and when the relevant compliance deadlines apply. This registry will also help you respond to any questions from regulators.

What are the consequences if an organization fails to comply with the AI Act?

Failure to comply with the AI Act may result in substantial fines. The amount depends on the type of violation: violations of prohibited practices may result in fines of up to 35 million euros or 7% of global annual revenue, whichever is higher. Non-compliance with other obligations can result in fines of up to 15 million euros or 3%.

In addition to financial penalties, there are also reputational risks. Organizations that violate the rules risk negative publicity and a loss of customer trust. Especially in customer service, where trust is paramount, this can have far-reaching consequences for customer retention.

Enforcement is carried out by national market surveillance authorities. In January 2026, Finland became the first Member State to formally grant enforcement powers. Other EU countries are following suit, which means that enforcement is becoming increasingly concrete and closer to home. For SMEs, incidentally, the lower of the fixed amount or the percentage always applies, which offers some protection for smaller organizations.

How do you prepare a customer service chatbot for AI Act compliance?

To prepare a customer service chatbot for AI Act compliance, first determine the risk level, then identify the corresponding obligations, and finally implement specific measures. Start with an AI assessment, conduct a risk analysis, and ensure that the transparency requirement is addressed immediately, as it is already in effect.

A practical approach consists of the following steps:

  • Take inventory of all AI systems in your customer service department and record them in an internal AI registry.
  • Define your role: Are you a deployer, or will you also become a provider as a result of these changes?
  • Classify the risk level of each chatbot based on its function and the decisions it supports.
  • Implement the transparency requirement by clearly stating during every interaction that the user is communicating with an AI.
  • Assign human supervision to trained employees who can intervene when necessary.
  • Retain logs of AI interactions for at least six months.
  • Inform your employees about the use of AI systems before they are put into operation.
  • Conduct a DPIA if the chatbot processes personal data, in accordance with your GDPR obligations.

Be sure to keep a close eye on the deadlines as well: most requirements for high-risk systems will become enforceable as of August 2, 2026, but the transparency requirement is already in effect.

How Pegamento Helps Ensure AI Act Compliance for Customer Service Chatbots

We understand that compliance issues surrounding an AI chatbot can seem complex, especially when you also have to keep your day-to-day customer service operations running at the same time. At Pegamento, we help you make this clear and manageable—without costly custom development—but with a smart combination of proven modules.

What we can do for you:

  • Risk classification and assessment of your existing and new AI applications in customer service.
  • Implementation of transparency mechanisms so that your chatbot immediately complies with the requirement to notify users.
  • Establish a system for human oversight with clear escalation procedures for complex or sensitive customer inquiries.
  • Agentic AI assistants that not only follow instructions but also take the initiative and act independently—representing an evolution from traditional RPA bots to self-thinking assistants that comply with the AI Act.
  • Everything under one roof: from development and implementation to management and support, without silos or complex supplier management.

Our solutions are built with a focus on security and compliance. We are ISO 27001 (information security), ISO 9001, and ISO 26000 certified, which means that governance and risk management are not an afterthought for us, but a cornerstone of our business. Would you like to know where your organization stands right now and what the next step is? Check out our Agentic AI solutions for customer service or contact us for a no-obligation consultation.

Frequently Asked Questions

Wat is het verschil tussen een deployer en een aanbieder onder de AI Act, en hoe weet ik welke rol mijn organisatie heeft?

Een deployer is een organisatie die een bestaand AI-systeem inzet onder eigen verantwoordelijkheid, zonder het systeem fundamenteel te wijzigen. Je wordt aanbieder zodra je het systeem ingrijpend aanpast, een nieuw doel geeft, of je eigen naam of merk eraan verbindt. Dit onderscheid is cruciaal: als aanbieder ben je verantwoordelijk voor technische documentatie, conformiteitsbeoordeling en CE-markering, verplichtingen die aanzienlijk zwaarder zijn dan die van een deployer. Twijfel je over jouw rol? Laat een juridische of technische expert de situatie beoordelen voordat je het systeem verder aanpast of uitrolt.

Moet mijn chatbot ook voldoen aan de AVG naast de AI Act, en hoe combineer ik die twee?

Ja, de AI Act en de AVG gelden naast elkaar en vullen elkaar aan. Als je chatbot persoonsgegevens verwerkt, zoals namen, e-mailadressen of klanthistorie, ben je ook gehouden aan de AVG-verplichtingen, waaronder het uitvoeren van een Data Protection Impact Assessment (DPIA). In de praktijk kun je beide efficiënt combineren door bij de risicoanalyse voor de AI Act direct ook de privacyrisico’s mee te nemen. Een gecombineerde aanpak bespaart tijd en zorgt voor een consistente governance-structuur binnen je organisatie.

Hoe weet ik of mijn chatbot per ongeluk toch als hoog-risico wordt geclassificeerd?

De twee belangrijkste triggers voor een hoog-risicoclassificatie zijn: profilering van individuele klanten, en het ondersteunen van beslissingen over toegang tot essentiële diensten zoals krediet, verzekeringen of noodoproepen. Controleer kritisch welke data je chatbot verzamelt en analyseert, en welke acties of aanbevelingen hij genereert op basis daarvan. Als je chatbot bijvoorbeeld klanten segmenteert op basis van gedrag en op grond daarvan verschillende aanbiedingen toont, of doorverwijst naar diensten met grote financiële of persoonlijke gevolgen, is een hoog-risicobeoordeling noodzakelijk. Wanneer je twijfelt, is het verstandig dit te laten toetsen door een expert.

Wat moet er precies in een intern AI-register staan, en hoe begin ik daarmee?

Een intern AI-register bevat minimaal: een beschrijving van elk AI-systeem dat je gebruikt, het doel en de functie ervan, jouw rol (deployer of aanbieder), het risiconiveau, de verantwoordelijke medewerker voor toezicht, de bewaartermijn van logs en de relevante compliance-deadlines. Begin eenvoudig met een gestructureerd spreadsheet of een bestaand GRC-tool (Governance, Risk u0026 Compliance) dat je organisatie al gebruikt. Het register hoeft niet perfect te zijn op dag één; het gaat erom dat je een levend document bijhoudt dat je kunt overleggen aan toezichthouders en dat intern zorgt voor duidelijkheid over verantwoordelijkheden.

Geldt de transparantieplicht ook als mijn chatbot een menselijke naam of avatar heeft?

Ja, juist dan is de transparantieplicht extra relevant. Als je chatbot een menselijke naam draagt, zoals ‘Lisa’ of ‘Tom’, of een realistische menselijke avatar heeft, bestaat het risico dat gebruikers denken met een echte medewerker te communiceren. De AI Act vereist dat de AI-identiteit duidelijk en tijdig wordt gemeld, ongeacht de presentatievorm van de chatbot. Een menselijke naam of avatar ontslaat je dus niet van de meldingsplicht; het maakt een expliciete melding aan het begin van het gesprek juist nog belangrijker.

Wat zijn de meest voorkomende fouten die organisaties maken bij het voorbereiden op AI Act-compliance?

De meest voorkomende fouten zijn: de transparantieplicht te laat of te onduidelijk implementeren (bijvoorbeeld alleen in de algemene voorwaarden), onderschatten wanneer een aanpassing van een bestaand systeem je juridisch aanbieder maakt, en het ontbreken van aantoonbaar menselijk toezicht. Daarnaast vergeten veel organisaties de logbewaarplicht van zes maanden of informeren ze medewerkers niet tijdig over het gebruik van AI-systemen. Een proactieve aanpak, waarbij je compliance-stappen documenteert en intern communiceert, voorkomt de meeste van deze valkuilen.

Hoe houd ik mijn AI Act-compliance actueel als de regelgeving of mijn chatbot verder evolueert?

AI Act-compliance is geen eenmalige exercitie, maar een doorlopend proces. Stel een vaste reviewcyclus in, bijvoorbeeld halfjaarlijks, waarbij je controleert of de functionaliteit van je chatbot is gewijzigd, of er nieuwe richtsnoeren zijn gepubliceerd door de Europese AI Office, en of de compliance-deadlines voor jouw systemen zijn verschoven. Wijs intern een verantwoordelijke aan, zoals een AI-coördinator of compliance officer, die wijzigingen bijhoudt en het AI-register actueel houdt. Abonneer je ook op updates van de relevante nationale toezichthouder, zodat je tijdig op de hoogte bent van nieuwe handhavingsontwikkelingen in Nederland.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.