Most AI applications in contact centers fall under the “low-risk” or “minimal-risk” categories under the EU AI Act. However, applications that make decisions regarding access to essential services or that involve the profiling of individuals are classified as “high-risk” and require strict compliance. In this article, we answer the most frequently asked questions about AI-driven contact center technology and the AI Act, so you know where your organization stands.
Under the AI Act, which risk category does contact center AI fall into?
Contact center AI generally falls into the “limited risk” or “minimal risk” category, but may be classified as “high risk” in specific cases. The risk category depends on what the system does, not on the technology itself. The AI Act has four levels: prohibited applications, high-risk AI, limited risk, and minimal risk.
Most chatbots, conversation summaries, and routing systems used daily in contact centers are classified as low-risk or minimal-risk. That does not mean there are no obligations, but the requirements are considerably less stringent than for high-risk applications.
It only becomes high-risk when you use AI for decisions that have direct consequences for people in vulnerable situations, such as assessing creditworthiness, handling emergency calls, or profiling individuals. These are situations that do indeed occur in some contact centers, for example, at insurance companies, utility companies, or government agencies.
Which AI applications in the contact center are considered high-risk?
A contact center AI application is considered high-risk if it falls under one of the eight domains listed in Annex III of the AI Act. For contact centers, three domains are most relevant: access to essential services, employment and workforce management, and biometrics. Systems that profile natural persons are always high-risk, without exception.
Specifically, this means that the following applications may be classified as high-risk:
- AI that assesses creditworthiness or insurance risk based on customer conversations or behavioral patterns
- AI that prioritizes or handles emergency calls, where delays can cause immediate harm
- Biometric identification systems that use voice recognition to identify or categorize individuals
- AI that evaluates or monitors employees for personnel decisions, such as performance reviews or termination
- Systems that profile individuals based on behavior, communication style, or other personal characteristics
It is important to distinguish between a system that supports decision-making and one that actually makes decisions. An AI that advises an employee on the best solution for a customer is different from an AI that independently determines whether a customer is entitled to compensation. The former may fall outside the high-risk category; the latter almost certainly does not.
Furthermore, emotion-recognition systems are prohibited in the workplace, unless a medical or safety exception applies. Therefore, AI that analyzes the emotional state of employees or customers to evaluate performance is simply not allowed.
Which AI applications are classified as posing a limited or minimal risk?
Most common contact center AI applications fall under the “limited” or “minimal” risk categories. “Limited” risk entails mild transparency requirements; “minimal” risk entails virtually no legal obligations. The distinction lies in the degree of interaction with people and the potential impact on their decisions.
Low-risk applications include:
- Chatbots and virtual assistants that interact with customers. In such cases, users must be informed that they are communicating with an AI system.
- AI-generated summaries of conversations that are shown to customers or employees
- Sentiment analysis used for reporting purposes, but not for individual decisions regarding people
Applications with minimal or no risk include:
- Automatic call routing based on keywords or menu options
- AI-powered knowledge bases that help employees find answers faster
- Quality monitoring of calls for internal training purposes, provided that no profiling takes place
- Predictive Analytics for Workforce Planning at the Aggregate Level
The transparency requirement for limited-risk scenarios is practical: customers need to know that they are talking to an AI. This is easy for most contact centers to implement, but it is a legal requirement that must not be overlooked.
What requirements apply to high-risk AI in contact centers?
For high-risk AI in contact centers, there are extensive obligations that depend on the role you play: provider or deployer. Providers bear the heaviest burden; deployers have fewer obligations, but they are certainly not exempt.
Requirements for Providers of High-Risk AI
If your organization develops or markets a high-risk AI system, the following requirements, among others, apply:
- A continuous risk management system throughout the entire system lifecycle
- Technical documentation in accordance with Annex IV of the AI Act
- Automatic logging of events, so that the system can be audited later
- A design that effectively enables human oversight, including awareness of automation bias
- A quality management system, a conformity assessment, and CE marking
- Registration in the EU database
Requirements for Deployers of High-Risk AI
If you use a high-risk AI system from a third-party provider in your contact center, you are considered a deployer. Your obligations are more limited, but not insignificant:
- Use the system only in accordance with the provider’s instructions for use
- Assign human supervision to qualified and trained individuals
- Retain logs for at least six months
- Informing employees before the system is put into use (Article 26(7))
- Conduct a data protection impact assessment (DPIA) where applicable
Furthermore, customers or employees who are subject to a decision made by a high-risk system have the right, under Article 86, to request an explanation of the factors that determined that decision. This means that, as a contact center, you must be able to provide that explanation.
Specifically, what steps do contact centers need to take now to become AI Act-compliant?
Contact centers must actively begin working on AI Act compliance in 2026, even though not all requirements are in effect yet. The most urgent step is to identify which AI systems you use and which risk category they fall into. Without that overview, targeted action is impossible.
A practical approach looks like this:
- Identify all AI applications. What systems do you use, what exactly do they do, and who developed them? Distinguish between systems you build yourself and systems you purchase from a vendor.
- Classify each system. Is it classified as minimal, moderate, or high risk? Use the criteria in Annex III as a guide, paying particular attention to profiling and decisions regarding essential services.
- Check transparency requirements. Do customers know they’re communicating with an AI system? If not, adjust your scripts and interfaces.
- Set up human oversight. Ensure that a trained employee is always responsible for supervising high-risk operations.
- Inform employees. Article 26(7) requires you to inform your employees before high-risk AI is put into use. Do this proactively and document it.
- Keep logs. For high-risk applications, a retention period of at least six months applies.
- Work together with your suppliers. As a deployer, you rely on the documentation and user manuals provided by your vendors. Be sure to actively request the necessary information and declarations of conformity.
Most of the requirements for high-risk Annex III systems will take effect on August 2, 2026. However, the prohibited practices and the AI literacy requirement have been in effect since February 2025. So don’t wait until the deadline—start your assessment now.
How Pegamento Helps Ensure AI Act Compliance in the Contact Center
Navigating the AI Act is complex, especially when you’re combining multiple AI applications in your contact center environment. We help organizations set up AI applications that are not only effective but also comply with applicable regulations. Our approach is built on smart combinations of proven modules, without costly custom development projects, and all under one roof.
Here’s what we specifically offer contact centers that want to operate in compliance with the AI Act:
- Transparent AI Communication: Our systems are configured by default to inform customers that they are communicating with an AI system
- Human oversight as a guiding principle: our Agentic AI assistants—the evolution from traditional RPA to self-thinking assistants that take the initiative on their own—are designed to support human employees, not to replace them
- Certified security: We are ISO 27001 certified (information security), supplemented by ISO 9001 and ISO 26000, which align with the security and documentation requirements of the AI Act
- A single point of contact: from implementation to management and compliance support—you don’t have to switch between multiple vendors
- Logging and reporting: Our solutions provide the data retention capabilities and reporting structures that deployers need for high-risk applications
Would you like to know how your current contact center AI applications align with the AI Act? Contact us, and we’d be happy to work with you to develop a compliant and future-proof solution.
Frequently Asked Questions
Wat gebeurt er als mijn contactcenter niet voldoet aan de AI Act?
Bij niet-naleving van de AI Act kunnen toezichthouders boetes opleggen die oplopen tot 35 miljoen euro of 7% van de wereldwijde jaaromzet, afhankelijk van de ernst van de overtreding. Voor deployers die hoog-risico systemen onjuist inzetten, gelden lagere maar nog steeds aanzienlijke sancties. Naast financiële gevolgen loop je ook reputatierisico’s, zeker als er sprake is van schendingen die klanten of medewerkers direct raken. Het is dus niet alleen een juridische kwestie, maar ook een bedrijfsrisico dat serieus genomen moet worden.
Geldt de AI Act ook voor kleine contactcenters of alleen voor grote organisaties?
De AI Act geldt in principe voor alle organisaties die AI-systemen inzetten of aanbieden binnen de EU, ongeacht hun omvang. Voor micro-ondernemingen en kleine bedrijven gelden wel enkele verlichte verplichtingen, met name aan de aanbiederskant. Als deployer — dus als je AI-systemen van een externe leverancier inzet — blijven de kernverplichtingen zoals transparantie, menselijk toezicht en logbeheer echter ook voor kleinere contactcenters van toepassing. De omvang van je organisatie bepaalt dus niet óf je moet voldoen, maar kan wel invloed hebben op de manier waarop bepaalde verplichtingen worden ingevuld.
Hoe weet ik of mijn AI-leverancier de juiste documentatie aanlevert voor compliance?
Vraag je leverancier expliciet om de technische documentatie conform Annex IV van de AI Act, de gebruiksaanwijzing (instructions for use) en, voor hoog-risico systemen, de EU-conformiteitsverklaring en bewijs van registratie in de EU-databank. Een betrouwbare aanbieder van hoog-risico AI kan deze documenten op verzoek overleggen. Als je leverancier deze informatie niet kan of wil verstrekken, is dat een serieus signaal dat je compliance als deployer in gevaar komt. Leg afspraken over documentatie en updates altijd contractueel vast.
Mijn contactcenter gebruikt sentimentanalyse op gesprekken. Is dat toegestaan onder de AI Act?
Sentimentanalyse is toegestaan, maar de toelaatbaarheid hangt sterk af van het doel waarvoor je het inzet. Gebruik je het uitsluitend voor geaggregeerde rapportage en kwaliteitsverbetering, dan valt het doorgaans onder beperkt of minimaal risico. Zodra de sentimentanalyse echter wordt gebruikt om individuele medewerkers of klanten te beoordelen, te profileren of om beslissingen over hen te nemen, kan het als hoog-risico worden aangemerkt of zelfs verboden zijn. Emotieherkenning op de werkvloer ter beoordeling van medewerkers is sowieso verboden onder de AI Act, dus zorg dat je het onderscheid goed documenteert en borgt.
Wat is de AI-geletterdheidsplicht en wat betekent dat praktisch voor mijn contactcentermedewerkers?
De AI-geletterdheidsplicht (Artikel 4 van de AI Act) is al van kracht sinds februari 2025 en verplicht organisaties om ervoor te zorgen dat medewerkers die met AI-systemen werken, voldoende kennis en begrip hebben van die systemen. In de praktijk betekent dit dat je contactcentermedewerkers getraind moeten worden in wat de AI-tools doen, wat hun beperkingen zijn en wanneer menselijk oordeel noodzakelijk is. Dit hoeft geen uitgebreide technische opleiding te zijn, maar een gerichte training die aansluit bij de rol van de medewerker is wel verplicht en moet worden gedocumenteerd.
Kunnen klanten bezwaar maken tegen een beslissing die door een AI-systeem in mijn contactcenter is genomen?
Ja, op grond van Artikel 86 van de AI Act hebben personen die zijn onderworpen aan een beslissing van een hoog-risico AI-systeem het recht om een betekenisvolle uitleg te vragen over de bepalende factoren van die beslissing. Als contactcenter moet je dus in staat zijn om op begrijpelijke wijze uit te leggen waarom een AI-systeem tot een bepaalde uitkomst is gekomen, zoals een afwijzing of prioritering. Dit vereist dat je systemen voldoende transparant en herleidbaar zijn ingericht. Combineer dit met een duidelijk intern escalatieproces zodat medewerkers weten hoe ze met dergelijke verzoeken omgaan.
Wat is het verschil tussen een aanbieder en een deployer, en welke rol heeft mijn contactcenter?
Een aanbieder (provider) is de partij die een AI-systeem ontwikkelt en op de markt brengt; een deployer is de organisatie die dat systeem in de eigen bedrijfsvoering inzet. De meeste contactcenters zijn deployer: ze kopen of licenseren AI-oplossingen van technologieleveranciers en zetten die in voor klantcontact. Als deployer ben je niet verantwoordelijk voor de ontwikkeling en certificering van het systeem, maar wel voor correct gebruik, menselijk toezicht, logbeheer en het informeren van medewerkers. In uitzonderlijke gevallen, bijvoorbeeld als je zelf AI-functionaliteit aanpast of intern ontwikkelt, kan je contactcenter ook als aanbieder worden aangemerkt, met aanzienlijk zwaardere verplichtingen als gevolg.


