{"id":32703,"date":"2026-07-23T08:00:00","date_gmt":"2026-07-23T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-inform-customers-about-automated-decision-making-in-accordance-with-the-ai-act\/"},"modified":"2026-07-23T10:00:49","modified_gmt":"2026-07-23T08:00:49","slug":"how-do-you-inform-customers-about-automated-decision-making-in-accordance-with-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-inform-customers-about-automated-decision-making-in-accordance-with-the-ai-act\/","title":{"rendered":"How do you inform customers about automated decision-making in accordance with the AI Act?"},"content":{"rendered":"<p>To inform customers about automated decision-making in accordance with the AI Act, you must communicate transparently about the use of AI, explain the logic behind decisions, and inform those affected of their rights. This applies to organizations that use AI systems that have legal consequences or significantly affect people in a similar manner. In this article, we answer the most frequently asked questions about <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">AI-driven decision-making<\/a> and the associated communication obligations.  <\/p>\n<h2>What obligations does the AI Act impose regarding automated decision-making?<\/h2>\n<p>The AI Act imposes transparency requirements on organizations that use high-risk AI systems for automated decision-making. Specifically, this means that you must inform data subjects about the use of AI, document how the system works, and ensure human oversight. The extent of these obligations depends on the system\u2019s risk category.  <\/p>\n<p>The AI Act uses four risk levels. Most applications fall into the \u201cminimal risk\u201d category and are largely unregulated. Systems with \u201climited risk,\u201d such as chatbots, are subject to less stringent transparency requirements. High-risk AI is strictly regulated, and prohibited applications are not permitted effective immediately.   <\/p>\n<p>The high-risk category is most relevant to automated decision-making. Examples include systems used for credit assessments, employee selection, access to essential services, or admission to educational institutions. These applications are subject to requirements such as:  <\/p>\n<ul>\n<li>Prepare and keep technical documentation up to date<\/li>\n<li>Implementing and maintaining a risk management system<\/li>\n<li>Making Human Oversight Technically Feasible<\/li>\n<li>Informing Data Subjects About the Use of the AI System<\/li>\n<li>Registration in the EU database for high-risk systems<\/li>\n<\/ul>\n<p>Most of the requirements for high-risk Annex III systems will take effect on August 2, 2026. Organizations that are already using such systems would be wise not to delay their preparations any longer. <\/p>\n<h2>Who should be informed about automated decisions?<\/h2>\n<p>In the case of automated decision-making, you must first inform the natural persons who are being assessed by the system or whose behavior is being predicted. These are the individuals directly affected: customers, job applicants, insured individuals, or citizens who are the subject of the AI decision. In addition, there are information requirements for regulators and, in certain cases, downstream providers.  <\/p>\n<p>In the context of customer contact, this specifically refers to people who reach out to your organization, where an automated system determines how their request is handled, what priority it is given, or what offer they receive. They need to know that an AI system is involved in the decision that affects them. <\/p>\n<p>For GPAI models\u2014such as large language models that are integrated into customer contact systems\u2014the model provider must also inform downstream parties about the model\u2019s capabilities and limitations. If your organization uses such a model, you, as the deployer, are responsible for communicating with end users. <\/p>\n<h2>What must a notice regarding automated decision-making include?<\/h2>\n<p>A notice regarding automated decision-making must, at a minimum, state that an AI system is being used, the purpose of that system, the logic or criteria guiding the decision, and the rights of the data subject. The information must be understandable to the average reader, not just to technical experts or lawyers. <\/p>\n<p>Specifically, a complete notification includes the following elements:<\/p>\n<ul>\n<li><strong>System Identification:<\/strong> What type of AI system is being used, and for what purpose?<\/li>\n<li><strong>Decision Logic:<\/strong> Which Factors or Data Influence the Outcome?<\/li>\n<li><strong>Consequences:<\/strong> What is the legal consequence or the substantive impact on the person concerned?<\/li>\n<li><strong>Rights of the data subject:<\/strong> right to an explanation, right to human intervention, right to object<\/li>\n<li><strong>Contact Information:<\/strong> How the data subject can reach a person with questions or objections<\/li>\n<\/ul>\n<p>For high-risk systems, the AI Act stipulates that the information must be available before the system makes a decision that affects the data subject. Providing information after the fact is insufficient in most cases. <\/p>\n<h2>How does the AI Act differ from the GDPR with regard to automated decisions?<\/h2>\n<p>The AI Act and the GDPR overlap in the area of automated decision-making, but they complement rather than replace each other. The GDPR grants data subjects the right not to be subject solely to automated decision-making with legal effects and establishes the right to a subsequent explanation. The AI Act imposes additional requirements on the development, documentation, and oversight of AI systems themselves, even before a decision is made.  <\/p>\n<h3>What does the GDPR cover?<\/h3>\n<p>The GDPR (Article 22) generally prohibits fully automated decision-making with legal effects, unless an exception applies, such as explicit consent or a contractual necessity. The data subject has the right to human intervention, the right to express their point of view, and the right to challenge the decision. The GDPR focuses on the rights of the individual after the decision has been made.  <\/p>\n<h3>What does the AI Act add?<\/h3>\n<p>The AI Act goes a step further by imposing requirements on the system itself, even before it is deployed. These include mandatory risk assessments, technical documentation, accuracy tests, and the incorporation of human oversight as a technical requirement. Whereas the GDPR provides protection through rights, the AI Act provides protection through system quality and transparency at the outset. Organizations must comply with both frameworks; compliance with the GDPR is not a substitute for compliance with the AI Act.   <\/p>\n<h2>How do you draft a clear customer notice about AI decisions?<\/h2>\n<p>Write a clear customer notice about AI decisions in plain language, from the customer\u2019s perspective. Avoid legal jargon and technical terms. Start with what the customer notices right away, explain why AI is being used, and make it clear what the customer can do if they disagree. Concrete and honest language builds more trust than formal disclaimers.   <\/p>\n<p>Practical guidelines for effective customer communication:<\/p>\n<ol>\n<li><strong>Use active voice:<\/strong> write &#8220;We use an automated system to&#8230;&#8221; instead of &#8220;An automated system is used to&#8230;&#8221;<\/li>\n<li><strong>Specify the goal in concrete terms:<\/strong> state what the system will be used for, such as prioritizing customer inquiries or evaluating an application<\/li>\n<li><strong>Avoid vague descriptions:<\/strong> &#8220;algorithm&#8221; without an explanation means nothing to a customer; describe what the system actually does<\/li>\n<li><strong>Explain rights in plain language:<\/strong> &#8220;You can always ask for a staff member to review your situation.&#8221;<\/li>\n<li><strong>Make it easy to find:<\/strong> ensure that the information is available when the customer needs it, not just in the terms and conditions<\/li>\n<\/ol>\n<p>Test the message with a small group of customers or employees who do not have a technical background. If they understand the text, you are likely complying with the spirit of the transparency requirement. <\/p>\n<h2>What are the consequences of non-compliance with the AI Act for customer communications?<\/h2>\n<p>Non-compliance with the AI Act regarding customer communication can result in significant fines, reputational damage, and mandatory changes to your systems. The fine structure has three tiers: violations of prohibited practices can result in fines of up to 35 million euros or 7% of global annual revenue; non-compliance with other obligations can result in fines of up to 15 million euros or 3%; and providing incorrect information to authorities can result in fines of up to 7.5 million euros or 1%. <\/p>\n<p>In addition to financial risks, there are also operational consequences. Regulators may require you to temporarily shut down or modify a system before you are allowed to put it back into use. In January 2026, Finland became the first member state to formally grant enforcement powers to its national authority. Other EU member states are following suit, which means that enforcement is becoming increasingly concrete and imminent.   <\/p>\n<p>For small and medium-sized organizations, the fine is capped at the lower of a fixed amount or a percentage of revenue. This offers some protection, but it does not exempt you from the obligation to comply. Proactively investing in proper customer communication is significantly less expensive than having to make corrections later under pressure from a regulatory authority.  <\/p>\n<h2>How Pegamento Helps with Automated Decision-Making and AI Act Compliance<\/h2>\n<p>If you\u2019re using AI in your customer interactions, you want to be sure that your systems are transparent, traceable, and compliant. We help organizations use <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">AI responsibly in customer service<\/a>, where compliance isn\u2019t an afterthought but an integral part of the solution. Our approach combines smart technology with clear governance\u2014without costly customization, but with proven modules that you can deploy quickly.  <\/p>\n<p>Specifically, we offer:<\/p>\n<ul>\n<li>Agentic AI assistants that take the initiative and act independently, but with human oversight always built in<\/li>\n<li>Omnichannel customer engagement solutions that manage all channels under one roof, including audit trails for automated decisions<\/li>\n<li>Support in drafting clear customer communications and internal documentation in accordance with the AI Act requirements<\/li>\n<li>Everything under one roof: from implementation to management, so you have a single point of contact and avoid a complex supplier structure<\/li>\n<\/ul>\n<p>Pegamento is ISO 27001 certified for information security, supplemented by ISO 9001 and ISO 26000, which means you can rely on a partner that takes quality and responsibility seriously. Would you like to know how your organization can prepare for the AI Act requirements? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019d be happy to help you figure it out. <\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Geldt de AI Act ook voor kleine bedrijven die slechts \u00e9\u00e9n AI-tool gebruiken in hun klantcontact?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, de AI Act is van toepassing op alle organisaties die AI-systemen inzetten binnen de EU, ongeacht hun omvang. Wel biedt de wet enige bescherming voor kleinere organisaties: boetes worden gemaximeerd op het laagste van het vaste bedrag of een percentage van de omzet. Toch ben je als klein bedrijf niet vrijgesteld van de transparantie- en documentatieverplichtingen als je een hoog-risico systeem inzet. Een eerste stap is bepalen in welke risicocategorie jouw AI-toepassing valt.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe weet ik of het AI-systeem dat ik gebruik als &#039;hoog-risico&#039; wordt geclassificeerd?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een AI-systeem valt in de hoog-risico categorie als het wordt ingezet voor toepassingen die zijn opgesomd in Bijlage III van de AI Act, zoals kredietbeoordeling, personeelselectie, toegang tot essenti\u00eble diensten of onderwijstoelating. Als jouw systeem beslissingen neemt die rechtsgevolgen hebben of mensen op een vergelijkbare wezenlijke manier treffen, is de kans groot dat het hoog-risico is. Raadpleeg bij twijfel de offici\u00eble EU-checklist of schakel juridisch of technisch advies in om de classificatie te bevestigen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat is de meest gemaakte fout bij het opstellen van een klantmededeling over AI-beslissingen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De meest voorkomende fout is het verstoppen van de AI-kennisgeving in de algemene voorwaarden of een privacyverklaring die klanten zelden lezen. De AI Act vereist dat informatie beschikbaar is op het moment dat het relevant is voor de betrokkene, dus v\u00f3\u00f3rdat of op het moment dat de beslissing plaatsvindt. Een tweede veelgemaakte fout is het gebruik van vage termen zoals &#8216;geautomatiseerde verwerking&#8217; zonder concreet uit te leggen wat het systeem doet en welke gevolgen dat heeft voor de klant.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Moeten wij ook voldoen aan de AI Act als wij een AI-tool inkopen bij een externe leverancier?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, als deployer (de organisatie die het AI-systeem inzet) blijf je verantwoordelijk voor de communicatie richting eindgebruikers en voor het waarborgen van menselijk toezicht, ook als het systeem is ontwikkeld door een externe aanbieder. De aanbieder is verantwoordelijk voor de technische documentatie en de conformiteit van het systeem zelf, maar jij bent verantwoordelijk voor de correcte inzet ervan. Zorg er bij de contractonderhandeling voor dat je leverancier de benodigde documentatie en informatie levert die jij nodig hebt om aan jouw eigen verplichtingen te voldoen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe combineer ik de verplichtingen uit de AI Act met de bestaande AVG-verplichtingen in de praktijk?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De meest praktische aanpak is om je bestaande AVG-documentatie als vertrekpunt te nemen en deze uit te breiden met de aanvullende AI Act-vereisten. Waar de AVG al een privacyverklaring en verwerkingsregister vereist, voeg je daar de AI-specifieke elementen aan toe: risicobeoordelingen, technische documentatie en transparantie-informatie over de beslissingslogica. Combineer de rechteninformatie voor betrokkenen in \u00e9\u00e9n begrijpelijk document, zodat klanten niet worden overspoeld met afzonderlijke juridische verklaringen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat houdt &#039;menselijk toezicht&#039; precies in en hoe implementeer ik dat technisch?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Menselijk toezicht betekent dat een medewerker altijd in staat moet zijn om een AI-beslissing te begrijpen, te controleren, te corrigeren of te negeren voordat deze definitief effect heeft op een betrokkene. Technisch gezien houdt dit in dat je systeem een &#8216;human-in-the-loop&#8217; of &#8216;human-on-the-loop&#8217; mechanisme moet bevatten, afhankelijk van de risicocategorie. Concreet kan dit een goedkeuringsstap zijn voor hoog-impact beslissingen, een dashboard waarop medewerkers AI-aanbevelingen kunnen reviewen, of een escalatiepad waarbij de klant altijd een menselijke medewerker kan bereiken.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wanneer moet mijn organisatie uiterlijk compliant zijn met de AI Act-verplichtingen voor hoog-risico systemen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De meeste verplichtingen voor hoog-risico Annex III-systemen treden in werking op 2 augustus 2026. Dat lijkt nog ver weg, maar de voorbereidingstijd voor risicobeoordelingen, technische documentatie, systeemaanpassingen en het opstellen van klantcommunicatie is aanzienlijk. Organisaties die nu al met hoog-risico AI werken, wordt aangeraden direct te starten met een gap-analyse om te bepalen welke aanpassingen nodig zijn en hoeveel tijd en middelen daarvoor nodig zijn.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The AI Act and Customer Communication: Find out what transparency requirements apply to automated decision-making before August 2026.<\/p>\n","protected":false},"author":2,"featured_media":32704,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32703","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32703"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32703\/revisions"}],"predecessor-version":[{"id":32706,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32703\/revisions\/32706"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32704"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}