When is a customer service chatbot considered high-risk under the AI Act?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

A customer service chatbot is considered high-risk under the EU AI Act if it makes or supports decisions that have significant implications for people’s rights or their access to essential services. This does not apply to most standard FAQ bots, but it does apply to chatbots that, for example, assess creditworthiness, process benefits, or handle emergency calls. In this article, we answer the most frequently asked questions about when a customer service AI chatbot falls into the high-risk category and what that means for your organization.

What criteria determine whether an AI system is high-risk?

An AI system is considered high-risk under the AI Act if it falls under one of the eight use cases listed in Annex III, or if it constitutes a safety component of a regulated product that requires a third-party conformity assessment. The Act provides two independent pathways to high-risk classification, and it is sufficient for a system to meet the criteria for either one.

The eight areas listed in Annex III are specifically defined and include: biometrics, critical infrastructure, education and vocational training, employment and human resources management, access to essential services (such as creditworthiness, insurance, and emergency calls), law enforcement, migration and border control, and the administration of justice and democratic processes.

There is, however, one exception: an Annex III system that performs only a narrow procedural or preparatory task and does not pose a significant risk to fundamental rights may fall outside the high-risk category. However, the provider must then document this with supporting evidence. Furthermore, there is a strict rule: systems that perform profiling of natural persons are always high-risk, without exception.

In practical terms, this means that the question “Is this system high-risk?” can never be answered purely from a technical standpoint. It’s about the intended use and the potential impact on people, not the technology itself.

Does a customer service chatbot fall under a high-risk category under the AI Act?

Most customer service chatbots do not automatically fall into a high-risk category. A chatbot that answers frequently asked questions, provides business hours, or registers a callback request typically has minimal impact on fundamental rights and falls outside the eight Annex III domains. Such systems are considered low-risk AI.

However, the classification changes as soon as a chatbot performs tasks that touch on the protected areas listed in Annex III. A chatbot at an insurance company that helps assess whether someone is eligible for a policy, or a bot at a municipality that determines whether a citizen is entitled to benefits, operates in the domain of access to essential services. That immediately places it in the high-risk category.

Another relevant factor is whether the chatbot performs profiling. If the system uses conversation data or user behavior to build a profile that influences future decisions, then the system is always high-risk, regardless of the sector in which it is used.

What makes a chatbot in the public sector high-risk?

A chatbot in the public sector is considered high-risk when it plays a role in decisions regarding access to government services, benefits, permits, or other citizens’ rights. Government agencies operate in areas that the AI Act explicitly designates as high-risk, which means the threshold for classification is lower than in commercial environments.

Consider a chatbot at a municipal office that handles questions about social assistance applications, or a bot at an implementing agency that guides citizens through appeal procedures. Even if the chatbot does not make a final decision itself but instead filters information or determines the path leading to a decision, it can be considered part of a high-risk AI system.

An additional risk in the public sector is the combination of scale and vulnerability. Government agencies serve large numbers of citizens, including people in financially or socially vulnerable situations. The AI Act places particular emphasis on that combination of reach and impact in its risk assessment.

How does a high-risk chatbot differ from a low-risk chatbot?

The key difference between a high-risk and a minimal-risk chatbot lies in the impact of the output on people. A minimal-risk chatbot provides information, answers questions, or facilitates a conversation without the outcome having any direct consequences for a person’s rights, opportunities, or access to services. A high-risk chatbot influences or supports decisions that do have such consequences.

In practical terms, you can explain the distinction as follows:

  • Low-risk: a chatbot that provides product information, answers FAQs, schedules an appointment, or logs a complaint
  • High-risk: a chatbot that helps determine whether someone is eligible for a loan, insurance, or benefits; that handles emergency calls; or that performs profiling based on conversation data

An important point to note: the classification is not static. A chatbot deployed today as low-risk may become high-risk as soon as its functionality is expanded or its intended purpose changes. The AI Act explicitly states that a deployer or third party becomes a provider—with all the associated obligations—when they modify the intended purpose of a system in such a way that it becomes high-risk.

What requirements apply to high-risk AI in customer service?

High-risk AI systems used in customer service are subject to extensive requirements regarding documentation, oversight, transparency, and risk management. Most of these requirements for Annex III systems will take effect on August 2, 2026, but preparations are necessary now.

The key obligations for providers of high-risk AI include, among other things:

  • Establish and maintain a robust risk management system throughout the system’s entire lifecycle
  • Prepare technical documentation demonstrating that the system complies with the requirements of the AI Act
  • Ensure data management, including quality control of training data
  • Build in logging and traceability so that the system can be audited later
  • Enabling human oversight: A person must always be able to override or shut down the system
  • Ensure adequate levels of accuracy, robustness, and cybersecurity
  • Registration in the EU database for high-risk AI systems

Deployers (organizations that use a high-risk AI system developed by another party) are subject to additional obligations: conducting a fundamental rights impact assessment before the system is put into use, informing employees about how the system works, and monitoring its performance in practice.

When does a transparency requirement apply to chatbots?

A transparency requirement applies to virtually every chatbot that interacts with people, regardless of whether the system is high-risk. The AI Act stipulates that users must be informed when they are interacting with an AI system, unless this is already clear from the context. This is a basic requirement that is already in effect and does not depend on a high-risk classification.

In practical terms, this means that a chatbot that mimics a human must always disclose that it is an AI system. This also applies to voice-activated systems and to bots that communicate on behalf of an organization via WhatsApp, chat, or email. The disclosure must be clear and understandable, not hidden in the fine print.

For high-risk chatbots, the transparency requirements are more extensive. Deployers must inform users that they are interacting with a high-risk AI system and, in certain cases, also explain the logic the system uses. When a chatbot supports a decision that has significant consequences for a person, that person has the right to a meaningful explanation.

A practical consideration: the transparency requirement also applies to internal applications. If your employees are supported by an AI system that evaluates their performance or assigns their tasks, that is also subject to the disclosure requirement under the AI Act.

How Pegamento Helps with AI Compliance in Customer Service

Navigating the AI Act is complex, especially if you also want to run a customer service operation that actually works. At Pegamento, we understand that challenge. We help organizations implement smart, AI-driven solutions that are not only effective but also comply with the requirements of the AI Act.

What we can do for you:

  • Mapping Risk Classification: Together, we’ll analyze which AI applications in your customer service fall under which risk categories
  • Building in transparency: We ensure that chatbots and AI assistants meet the basic requirements for transparency and human oversight
  • Documentation and logging: We set up systems with the proper traceability and audit trails you need to ensure compliance
  • Customized solutions using standard building blocks: no costly custom work, but a smart combination of proven modules that you can deploy quickly and easily
  • Everything under one roof: from consulting and implementation to management and support—a single point of contact for the complete package

Our AI assistants are built on the principle of Agentic AI: an evolution from executive bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently. That makes them powerful—and requires the right governance. Would you like to know where your organization stands and how to use AI responsibly in customer service? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Hoe weet ik of mijn bestaande chatbot opnieuw beoordeeld moet worden na een functie-uitbreiding?

Zodra je de functionaliteit van een chatbot uitbreidt — bijvoorbeeld door hem te koppelen aan een beslissingsmodule of door klantprofielen op te laten bouwen — moet je de risicoclassificatie opnieuw uitvoeren. De AI Act stelt expliciet dat een wijziging in het beoogde doel kan leiden tot een nieuwe classificatie, waarbij de deployer zelf aanbieder wordt met alle bijbehorende verplichtingen. Praktisch advies: documenteer bij elke significante update het beoogde doel en toets dit aan de Annex III-domeinen voordat je de wijziging live zet.

Wat is het verschil tussen een aanbieder en een deployer onder de AI Act, en waarom maakt dat uit voor mijn organisatie?

Een aanbieder is de partij die het AI-systeem ontwikkelt en op de markt brengt, terwijl een deployer de organisatie is die het systeem in gebruik neemt voor een specifiek doel. Dit onderscheid is cruciaal omdat deployers eigen verplichtingen hebben, zoals het uitvoeren van een grondrechteneffectbeoordeling vóór ingebruikname en het monitoren van de prestaties in de praktijk. Bovendien kan een deployer automatisch de rol van aanbieder overnemen — met alle zwaardere compliance-eisen — als hij het beoogde doel van een ingekocht systeem zodanig aanpast dat het hoog-risico wordt.

Moet ik al actie ondernemen, of kan ik wachten tot de verplichtingen voor hoog-risico AI in augustus 2026 ingaan?

Wachten tot augustus 2026 is een risico, geen strategie. De voorbereidingstijd voor hoog-risico compliance — denk aan het opzetten van een risicobeheersysteem, het inrichten van logging en het opstellen van technische documentatie — is aanzienlijk en loopt al snel op tot meerdere maanden. Bovendien geldt de transparantieverplichting voor chatbots al nu: gebruikers moeten vandaag al geïnformeerd worden dat ze met een AI-systeem communiceren. Begin dus nu met een risicoclassificatie van je huidige AI-toepassingen.

Wat houdt een grondrechteneffectbeoordeling precies in, en hoe voer ik die uit?

Een grondrechteneffectbeoordeling (Fundamental Rights Impact Assessment, FRIA) is een gestructureerde analyse waarbij je in kaart brengt welke grondrechten van mensen mogelijk geraakt worden door jouw hoog-risico AI-systeem, hoe groot die impact is en welke maatregelen je neemt om risico’s te beperken. De beoordeling moet worden uitgevoerd vóórdat je een hoog-risico systeem in gebruik neemt en dient gedocumenteerd te worden. Concreet kijk je naar zaken als non-discriminatie, privacy, toegang tot rechtsmiddelen en de bescherming van kwetsbare groepen — en je legt vast hoe het systeem elk van deze aspecten beïnvloedt.

Geldt de transparantieverplichting ook als mijn chatbot duidelijk als 'virtuele assistent' is gelabeld op de website?

Een label zoals ‘virtuele assistent’ of ‘chatbot’ in de interface kan voldoende zijn als het voor een gemiddelde gebruiker onmiskenbaar duidelijk is dat hij met een AI-systeem communiceert. De AI Act stelt dat de melding niet verplicht is wanneer dit ‘evident blijkt uit de context’. Toch is voorzichtigheid geboden: de beoordeling of iets ‘evident’ is, ligt bij de toezichthouder, niet bij jou. Een expliciete, begrijpelijke vermelding aan het begin van het gesprek — zoals ‘U spreekt met een AI-assistent’ — is de veiligste aanpak en voorkomt discussie.

Wat zijn de meest gemaakte fouten bij het classificeren van een klantenservice chatbot onder de AI Act?

De meest voorkomende fout is redeneren vanuit de technologie in plaats van vanuit het gebruik: organisaties concluderen dat hun chatbot ‘gewoon een taalmodel’ is en daarmee minimaal-risico, terwijl de daadwerkelijke toepassing wel degelijk in een Annex III-domein valt. Een tweede veelgemaakte fout is het negeren van indirecte invloed: een chatbot die niet zelf beslist, maar die de informatie filtert of de routing bepaalt die tot een beslissing leidt, kan alsnog als onderdeel van een hoog-risico systeem worden aangemerkt. Ten slotte onderschatten veel organisaties het profilerings-criterium — zodra een systeem op basis van gespreksdata een gebruikersprofiel opbouwt, is het altijd hoog-risico.

Hoe ga ik om met een chatbot die zowel minimaal-risico als hoog-risico taken uitvoert binnen één platform?

Als één chatbot zowel eenvoudige FAQ-vragen beantwoordt als taken uitvoert die raken aan Annex III-domeinen, dan geldt de strengste classificatie voor het gehele systeem. Je kunt dit oplossen door de hoog-risico functionaliteit architectureel te scheiden in een afzonderlijk systeem met eigen governance, logging en documentatie, terwijl de minimaal-risico component lichter beheerd wordt. Dit vraagt om een bewuste ontwerpkeuze en heldere functionele grenzen tussen de twee componenten — iets wat je het beste vastlegt in de technische documentatie die de AI Act toch al vereist voor hoog-risico systemen.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.