{"id":32395,"date":"2026-07-16T08:00:00","date_gmt":"2026-07-16T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/what-steps-do-you-need-to-take-to-ensure-compliance-with-the-ai-act-as-a-customer-service-organization\/"},"modified":"2026-07-16T10:00:37","modified_gmt":"2026-07-16T08:00:37","slug":"what-steps-do-you-need-to-take-to-ensure-compliance-with-the-ai-act-as-a-customer-service-organization","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/what-steps-do-you-need-to-take-to-ensure-compliance-with-the-ai-act-as-a-customer-service-organization\/","title":{"rendered":"What steps do you need to take to ensure compliance with the AI Act as a customer service organization?"},"content":{"rendered":"<p>As a customer service organization, the first step toward AI Act compliance is to identify which AI systems you use, which risk category they fall into, and what obligations apply to them. The EU AI Act (Regulation (EU) 2024\/1689) is the world\u2019s first comprehensive AI regulation and applies to anyone who creates, uses, or deploys AI systems within the EU. In this article, we answer the most frequently asked questions about what compliance specifically means for your organization, from risk classification to documentation and liability. Also check out our page on <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">AI-driven intelligence<\/a> for more context on how AI is used in practice in customer interactions.   <\/p>\n<h2>Which AI systems used in customer service are covered by the AI Act?<\/h2>\n<p>Most AI systems used by customer service organizations fall under the AI Act, but the risk level varies greatly depending on the application. Chatbots and virtual assistants that transparently disclose that they are automated generally fall into the low-risk category. Systems that profile customers or make decisions regarding access to services may be classified as high-risk.  <\/p>\n<p>Specifically, there are four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (minimal transparency requirements), and minimal risk (largely unregulated). For customer service, the most relevant categories are: <\/p>\n<ul>\n<li><strong>Chatbots and virtual assistants:<\/strong> limited risk, but you are required to inform users that they are communicating with an AI system.<\/li>\n<li><strong>Systems that score or profile customers:<\/strong> always high-risk, regardless of the purpose. Think of tools that analyze customer behavior to determine priority or access. <\/li>\n<li><strong>AI for human resources management or scheduling:<\/strong> falls under the high-risk category of Annex III (employment and human resources management).<\/li>\n<li><strong>Emotion recognition among employees or customers:<\/strong> prohibited in the workplace, except for strictly defined exceptions for medical or safety purposes.<\/li>\n<li><strong>Systems for emergency calls or access to essential services:<\/strong> high risk under Annex III.<\/li>\n<\/ul>\n<p>A system that performs only a narrow procedural or preparatory task and does not pose a significant risk to fundamental rights may fall outside the high-risk category. However, this requires that your organization document this in a well-reasoned manner. <\/p>\n<h2>What are the requirements for high-risk AI applications?<\/h2>\n<p>If an AI system used in your customer service is classified as high-risk, extensive obligations apply regarding transparency, documentation, human oversight, and risk management. These obligations apply to both the provider and the user (deployer) of the system, each in their respective roles. <\/p>\n<p>The key obligations for high-risk AI are:<\/p>\n<ul>\n<li><strong>Risk Management System:<\/strong> You must identify, analyze, and mitigate risks throughout the system&#8217;s entire lifecycle.<\/li>\n<li><strong>Technical documentation:<\/strong> a detailed description of the system, its intended purpose, training data, and performance.<\/li>\n<li><strong>Logging and traceability:<\/strong> automatic logging of events so that regulators can review how decisions were reached after the fact.<\/li>\n<li><strong>Transparency for users:<\/strong> clear instructions on how the system works, what its limitations are, and how human oversight is organized.<\/li>\n<li><strong>Human oversight:<\/strong> A person must always be able to intervene, pause the system, or correct decisions.<\/li>\n<li><strong>Accuracy, robustness, and cybersecurity:<\/strong> the system must be demonstrably accurate and resistant to errors and misuse.<\/li>\n<\/ul>\n<p>Systems that profile natural persons are always high-risk. This is a strict rule with no exceptions, so it is important to thoroughly assess whether your systems do this. <\/p>\n<h2>When must an organization comply with the AI Act?<\/h2>\n<p>The AI Act will take effect in phases. Starting February 2, 2025, the prohibitions on unacceptable AI practices and the requirement for AI literacy within your organization will take effect. Most of the requirements for high-risk systems will take effect on August 2, 2026.  <\/p>\n<p>The timeline that is most relevant to customer service organizations is as follows:<\/p>\n<ol>\n<li><strong>February 2, 2025 (already in effect):<\/strong> Prohibited practices are no longer allowed, and you are required to ensure that employees who work with AI have sufficient AI literacy.<\/li>\n<li><strong>August 2, 2025 (already in effect):<\/strong> Requirements for providers of General Purpose AI models (such as large language models) are in effect. Penalty provisions are also already in effect. <\/li>\n<li><strong>August 2, 2026:<\/strong> Most of the requirements for high-risk systems listed in Annex III will take effect. This is the most important deadline for most customer service organizations. <\/li>\n<li><strong>August 2, 2027:<\/strong> Requirements for high-risk AI used as a safety component in regulated products take effect.<\/li>\n<\/ol>\n<p>So in 2026\u2014the current year\u2014it\u2019s important to get serious about your compliance efforts if you use high-risk systems. Don\u2019t wait until the deadline, because setting up documentation, risk management, and internal processes takes more time than you might think. <\/p>\n<h2>Who is responsible for AI Act compliance: the supplier or the user?<\/h2>\n<p>Both the provider (the party that develops or markets the AI system) and the deployer (the organization that deploys the system) have their own obligations under the AI Act. As a customer service organization, you are typically the deployer, but that does not exempt you from responsibility. <\/p>\n<p>The division of responsibilities works as follows:<\/p>\n<ul>\n<li><strong>The supplier<\/strong> is responsible for the conformity assessment, technical documentation, CE marking (for high-risk systems), and informing deployers about the system&#8217;s capabilities and limitations.<\/li>\n<li><strong>The deployer (your organization)<\/strong> is responsible for using the system correctly in accordance with the provider\u2019s instructions, organizing human oversight, informing employees and customers, and reporting serious incidents.<\/li>\n<\/ul>\n<p>There is one important point to note: if, as an organization, you substantially modify an AI system, brand it with your own name, or change its intended purpose in such a way that it becomes high-risk, you yourself become the provider, with all the associated obligations. This is a common misconception that can lead to unexpected liability. <\/p>\n<p>For every AI tool you purchase, verify that the supplier is demonstrably compliant. Ask for technical documentation, declarations of conformity, and details on how they address the obligations under the AI Act. <\/p>\n<h2>How do you document AI usage for regulators?<\/h2>\n<p>As an organization, you must be able to demonstrate to regulators which AI systems you use, for what purposes, how human oversight is organized, and how you manage risks. Proper documentation is the backbone of AI Act compliance and begins with a clear inventory of all AI applications within your organization. <\/p>\n<p>A practical approach to documentation involves the following steps:<\/p>\n<ol>\n<li><strong>AI Inventory:<\/strong> Create a list of all the AI systems you use, including chatbots, routing algorithms, analytics software, and any built-in AI in your CRM or contact center platform.<\/li>\n<li><strong>Risk classification by system:<\/strong> Determine the risk level for each system based on the criteria set forth in the AI Act. Document your reasoning, even if you conclude that a system does not pose a high risk. <\/li>\n<li><strong>Usage log:<\/strong> Keep track of how and for what purpose each system is used, who has access to it, and how decisions are made or supported.<\/li>\n<li><strong>Incident and Complaint Log:<\/strong> Document any errors, complaints from customers or employees, and how you responded to them.<\/li>\n<li><strong>Human oversight:<\/strong> Specify who is responsible for overseeing each system and how intervention works in practice.<\/li>\n<li><strong>Retention Requirement:<\/strong> You must retain technical documentation and declarations of conformity from suppliers for ten years.<\/li>\n<\/ol>\n<p>Employee AI literacy is also a documentation requirement. You must be able to demonstrate that employees who work with AI systems have sufficient knowledge to evaluate the output and understand when human intervention is necessary. <\/p>\n<h2>What are the consequences of noncompliance with the AI Act?<\/h2>\n<p>The fines for noncompliance with the AI Act are substantial and are already in effect. Violations of the prohibited practices listed in Article 5 may result in a fine of up to 35 million euros or 7% of global annual revenue, whichever is higher. <\/p>\n<p>The penalty structure has three levels:<\/p>\n<ul>\n<li><strong>Prohibited practices (Article 5):<\/strong> up to 35 million euros or 7% of global annual revenue.<\/li>\n<li><strong>Non-compliance with other obligations:<\/strong> up to 15 million euros or 3% of global annual revenue.<\/li>\n<li><strong>Inaccurate or misleading information provided to authorities:<\/strong> up to 7.5 million euros or 1% of global annual revenue.<\/li>\n<\/ul>\n<p>In addition to financial penalties, there are also reputational risks. Regulators may decide to make enforcement actions public, which could damage trust among customers and employees. In the Netherlands, enforcement powers are vested in national market supervisory authorities, which means that interpretation and prioritization may vary by member state.  <\/p>\n<p>For smaller organizations, the lower of the percentage-based amount or the fixed amount always applies when it comes to fines. Even so, a lower fine is still a significant financial blow, aside from the operational disruption caused by an investigation. <\/p>\n<h2>How Pegamento Helps Ensure AI Act Compliance in Customer Service<\/h2>\n<p>AI Act compliance is not a one-time project but an ongoing process that requires the right technology, clear processes, and demonstrable oversight. We help customer service organizations use AI responsibly, with solutions built from proven modules that eliminate the need for costly customization. Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a> is a good example: whereas traditional RPA relied on executional bots that followed instructions, we now position this as Agentic AI\u2014self-thinking assistants that take initiative on their own, understand context, and act without every step needing to be pre-programmed.  <\/p>\n<p>Here&#8217;s what you can expect from us in terms of AI compliance:<\/p>\n<ul>\n<li><strong>Transparent systems:<\/strong> Our solutions are designed with human oversight as a core principle, not as an afterthought.<\/li>\n<li><strong>Everything under one roof:<\/strong> from implementation to management and support\u2014a single point of contact without the complexity of supplier management.<\/li>\n<li><strong>Documentation support:<\/strong> We\u2019ll help you map out your AI usage and set up the necessary records.<\/li>\n<li><strong>ISO 27001 certified:<\/strong> Information security is our top priority, complemented by ISO 9001 and ISO 26000 for quality and social responsibility.<\/li>\n<li><strong>Risk Classification:<\/strong> Together, we\u2019ll assess which systems fall into which category and what that means for your organization.<\/li>\n<\/ul>\n<p>Would you like to know where your organization stands in terms of AI Act compliance and how to take the right steps, one by one? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019d be happy to help you figure it out.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Moet ik als kleine of middelgrote klantenserviceorganisatie ook voldoen aan de AI Act?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, de AI Act geldt voor alle organisaties die AI-systemen gebruiken binnen de EU, ongeacht de omvang. Er is wel een beperkte uitzondering voor micro-ondernemingen bij sommige verplichtingen, maar de kernverplichtingen zoals het naleven van verboden praktijken en het waarborgen van AI-geletterdheid gelden ook voor kleine organisaties. Juist voor kleinere organisaties is het verstandig om vroeg te beginnen, omdat de capaciteit om documentatie en processen op te zetten doorgaans beperkter is.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe weet ik of de AI die al ingebouwd zit in mijn CRM of contactcenterplatform ook onder de AI Act valt?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, ook ingebouwde AI-functionaliteiten in platforms zoals je CRM of contactcenteroplossing vallen onder de AI Act als ze aan de definitie van een AI-systeem voldoen. Vraag je leverancier expliciet welke AI-componenten in het platform zijn verwerkt, hoe deze zijn geclassificeerd en of de leverancier een conformiteitsverklaring kan overleggen. Als deployer ben jij mede verantwoordelijk voor het correct gebruik van deze systemen, ook al heb je ze niet zelf gebouwd.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat is het verschil tussen een AI-systeem en gewone automatisering, en hoe weet ik welke categorie mijn tool heeft?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act hanteert een specifieke definitie: een AI-systeem is een systeem dat op basis van input redeneert, voorspelt, aanbevelingen doet of beslissingen neemt op een manier die verder gaat dan eenvoudige regelgebaseerde automatisering. Traditionele RPA die vaste regels volgt zonder leren of redeneren, valt doorgaans buiten de definitie. Twijfel je over een specifiek systeem? Raadpleeg de offici\u00eble definitie in Artikel 3 van de AI Act en leg je redenering vast in je documentatie, ook als je concludeert dat het g\u00e9\u00e9n AI-systeem is.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik praktisch regelen rondom de AI-geletterdheidsplicht die al geldt sinds februari 2025?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI-geletterdheidsplicht houdt in dat je aantoonbaar moet zorgen dat medewerkers die met AI-systemen werken voldoende kennis hebben om de output te begrijpen, kritisch te beoordelen en te herkennen wanneer menselijk ingrijpen nodig is. Praktisch betekent dit: stel een basistraining op over de AI-tools die je gebruikt, documenteer wie welke training heeft gevolgd en zorg dat medewerkers weten hoe ze fouten of afwijkingen kunnen signaleren en escaleren. Een interne kennissessie of e-learning module is al een goede eerste stap die je kunt documenteren.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik doen als een klant vraagt of hij met een AI-systeem praat en hoe leg ik dit correct vast?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Onder de AI Act ben je verplicht om gebruikers te informeren wanneer ze met een AI-systeem communiceren, zoals een chatbot of virtuele assistent. Dit moet duidelijk, begrijpelijk en tijdig gebeuren, bij voorkeur aan het begin van de interactie. Leg in je documentatie vast hoe en wanneer deze melding wordt gedaan, in welk kanaal en via welke formulering. Zorg ook dat klanten altijd de mogelijkheid hebben om een menselijke medewerker te bereiken, en documenteer hoe dit in de praktijk is georganiseerd.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe ga ik om met een AI-systeem dat ik van een leverancier inkoop maar waarvan ik twijfel of het compliant is?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Vraag je leverancier proactief om een conformiteitsverklaring, technische documentatie en een toelichting op hoe zij invulling geven aan de verplichtingen onder de AI Act. Leg deze informatie vast in je eigen documentatie en maak compliance-vereisten onderdeel van je inkoopcontracten en Service Level Agreements. Als een leverancier geen duidelijkheid kan geven over compliance, is dat een serieus risicosignaal: als deployer kun je namelijk ook aansprakelijk worden gesteld als je een niet-compliant systeem blijft inzetten.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Kan ik mijn bestaande privacydocumentatie (AVG\/GDPR) hergebruiken voor AI Act-compliance, of moet ik alles opnieuw opbouwen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Je kunt bestaande AVG-documentatie zeker als vertrekpunt gebruiken, maar de AI Act stelt aanvullende en deels andere eisen. Zo vereist de AI Act specifieke technische documentatie over het AI-systeem zelf, een risicomanagementsysteem gericht op grondrechten en veiligheid, en logging van beslissingen die verder gaat dan wat de AVG vereist. Praktisch advies: gebruik je bestaande registers en DPIA-methodiek als basis, maar vul deze aan met de AI Act-specifieke elementen zoals risicoclassificatie, menselijk toezicht en bewaarplicht voor technische documentatie van tien jaar.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI Act Compliance for Customer Service: What You Need to Do Now Before the 2026 Deadline.<\/p>\n","protected":false},"author":2,"featured_media":32396,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32395","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32395"}],"version-history":[{"count":1,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32395\/revisions"}],"predecessor-version":[{"id":32397,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32395\/revisions\/32397"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32396"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}