{"id":32836,"date":"2026-07-24T08:00:00","date_gmt":"2026-07-24T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/what-does-the-ai-act-say-about-the-use-of-chatbots-in-customer-service\/"},"modified":"2026-07-24T10:00:48","modified_gmt":"2026-07-24T08:00:48","slug":"what-does-the-ai-act-say-about-the-use-of-chatbots-in-customer-service","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/what-does-the-ai-act-say-about-the-use-of-chatbots-in-customer-service\/","title":{"rendered":"What does the AI Act say about the use of chatbots in customer service?"},"content":{"rendered":"<p>The EU AI Act imposes specific obligations on companies that use an <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">AI chatbot<\/a> in their customer service, but the extent of these obligations depends on the chatbot\u2019s risk level. For most customer service chatbots, the primary requirements are transparency obligations: users must be aware that they are communicating with an AI. Below, we answer the most frequently asked questions about what the AI Act specifically means for your organization.  <\/p>\n<h2>What obligations does the AI Act impose on companies that use chatbots?<\/h2>\n<p>The AI Act imposes at least a transparency requirement on companies that use an AI chatbot: users must always know that they are communicating with an AI system and not with a human. Depending on the chatbot\u2019s risk level, additional, more stringent obligations may apply, such as risk management, technical documentation, and human oversight. <\/p>\n<p>As a deployer\u2014the party that deploys an AI system under its own responsibility\u2014you are required to use the system as intended by the provider. Furthermore, you must assign human oversight to competent and trained employees, retain logs for at least six months, and inform your employees before the system is put into use. This is outlined in Article 26 of the regulation.  <\/p>\n<p>Important to know: If you modify an existing AI system so significantly that it is given a new purpose, or if you put your own name on the system, you legally become the provider yourself. This entails significantly more stringent obligations, such as preparing technical documentation, conducting a conformity assessment, and affixing a CE marking. <\/p>\n<h2>What risk level will customer service chatbots be assigned under the AI Act?<\/h2>\n<p>Most customer service chatbots fall under the <strong>\u201climited risk\u201d<\/strong> category in the AI Act. This means they are not prohibited and do not have to meet the strict requirements for high-risk AI, but they are subject to less stringent transparency obligations. Only chatbots that make decisions regarding access to essential services, such as credit or insurance, are classified as high-risk.  <\/p>\n<p>The AI Act distinguishes four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (transparency requirements), and minimal risk (virtually unregulated). A standard chatbot that answers questions, refers customers, or provides information typically falls into the limited-risk category. <\/p>\n<p>Please note: as soon as a chatbot performs profiling of individual customers, it is automatically considered high-risk. This also applies if the chatbot plays a role in decisions regarding access to services deemed essential, such as emergency calls or insurance. In such cases, all high-risk obligations apply, including a risk management system, technical documentation, and a conformity assessment.  <\/p>\n<h2>What is the transparency requirement for chatbots, and how does it work in practice?<\/h2>\n<p>The transparency requirement means that you must <strong>clearly and promptly<\/strong> inform users that they are interacting with an AI system, not a human. This must be done at the start of the interaction, so that the user can make an informed decision about how to proceed. You may not hide this information in fine print or somewhere at the bottom of a page.  <\/p>\n<p>In practice, this means that your chatbot must explicitly state at the start of a conversation that it is an AI. A message such as &#8220;You are now chatting with our virtual assistant&#8221; or &#8220;This is an automated AI chatbot&#8221; meets the requirements. The message must be understandable to the average user, so avoid technical jargon.  <\/p>\n<p>There is one exception: if the user has specifically requested that an AI be used, or if its use is self-evident to the user, the requirement for explicit notification does not apply. In most customer service environments, however, that clarity is not self-evident, so an explicit notification is the safest approach. <\/p>\n<h2>Does the AI Act also apply to chatbots that are already in use?<\/h2>\n<p>Yes, the AI Act also applies to existing AI chatbots, but there is a transition period. Systems that were already on the market before August 2, 2025, do not have to be fully compliant until August 2, 2027, at the latest. However, the transparency requirement and the prohibited practices will take effect in August 2025 and February 2025, respectively.  <\/p>\n<p>This means you need to take action now, even if your chatbot has been up and running for years. The first step is to take stock of all AI systems within your organization and determine what role you play in them: are you a deployer, provider, importer, or distributor? Next, assess the risk level for each system and identify the resulting obligations.  <\/p>\n<p>Organizations would be wise to maintain an internal AI registry. In it, you document which systems you use, what their purpose is, who is responsible for oversight, and when the relevant compliance deadlines apply. This registry will also help you respond to any questions from regulators.  <\/p>\n<h2>What are the consequences if an organization fails to comply with the AI Act?<\/h2>\n<p>Failure to comply with the AI Act may result in substantial fines. The amount depends on the type of violation: violations of prohibited practices may result in fines of up to 35 million euros or 7% of global annual revenue, whichever is higher. Non-compliance with other obligations can result in fines of up to 15 million euros or 3%.  <\/p>\n<p>In addition to financial penalties, there are also reputational risks. Organizations that violate the rules risk negative publicity and a loss of customer trust. Especially in customer service, where trust is paramount, this can have far-reaching consequences for customer retention.  <\/p>\n<p>Enforcement is carried out by national market surveillance authorities. In January 2026, Finland became the first Member State to formally grant enforcement powers. Other EU countries are following suit, which means that enforcement is becoming increasingly concrete and closer to home. For SMEs, incidentally, the lower of the fixed amount or the percentage always applies, which offers some protection for smaller organizations.   <\/p>\n<h2>How do you prepare a customer service chatbot for AI Act compliance?<\/h2>\n<p>To prepare a customer service chatbot for AI Act compliance, first determine the risk level, then identify the corresponding obligations, and finally implement specific measures. Start with an AI assessment, conduct a risk analysis, and ensure that the transparency requirement is addressed immediately, as it is already in effect. <\/p>\n<p>A practical approach consists of the following steps:<\/p>\n<ul>\n<li><strong>Take inventory of<\/strong> all AI systems in your customer service department and record them in an internal AI registry.<\/li>\n<li><strong>Define your role:<\/strong> Are you a deployer, or will you also become a provider as a result of these changes?<\/li>\n<li><strong>Classify the risk level<\/strong> of each chatbot based on its function and the decisions it supports.<\/li>\n<li><strong>Implement the transparency requirement<\/strong> by clearly stating during every interaction that the user is communicating with an AI.<\/li>\n<li><strong>Assign human supervision<\/strong> to trained employees who can intervene when necessary.<\/li>\n<li><strong>Retain logs<\/strong> of AI interactions for at least six months.<\/li>\n<li><strong>Inform your employees<\/strong> about the use of AI systems before they are put into operation.<\/li>\n<li><strong>Conduct a DPIA<\/strong> if the chatbot processes personal data, in accordance with your GDPR obligations.<\/li>\n<\/ul>\n<p>Be sure to keep a close eye on the deadlines as well: most requirements for high-risk systems will become enforceable as of August 2, 2026, but the transparency requirement is already in effect.<\/p>\n<h2>How Pegamento Helps Ensure AI Act Compliance for Customer Service Chatbots<\/h2>\n<p>We understand that compliance issues surrounding an AI chatbot can seem complex, especially when you also have to keep your day-to-day customer service operations running at the same time. At Pegamento, we help you make this clear and manageable\u2014without costly custom development\u2014but with a smart combination of proven modules. <\/p>\n<p>What we can do for you:<\/p>\n<ul>\n<li><strong>Risk classification and assessment<\/strong> of your existing and new AI applications in customer service.<\/li>\n<li><strong>Implementation of transparency mechanisms<\/strong> so that your chatbot immediately complies with the requirement to notify users.<\/li>\n<li><strong>Establish a system for human oversight<\/strong> with clear escalation procedures for complex or sensitive customer inquiries.<\/li>\n<li><strong>Agentic AI assistants<\/strong> that not only follow instructions but also take the initiative and act independently\u2014representing an evolution from traditional RPA bots to self-thinking assistants that comply with the AI Act.<\/li>\n<li><strong>Everything under one roof:<\/strong> from development and implementation to management and support, without silos or complex supplier management.<\/li>\n<\/ul>\n<p>Our solutions are built with a focus on security and compliance. We are ISO 27001 (information security), ISO 9001, and ISO 26000 certified, which means that governance and risk management are not an afterthought for us, but a cornerstone of our business. Would you like to know where your organization stands right now and what the next step is? Check out our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI solutions for customer service<\/a> or <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">contact us<\/a> for a no-obligation consultation.   <\/p>\n        <div class=\"wp-block-seoaic-faq-block\">\n            <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n                            <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What is the difference between a deployer and a provider under the AI Act, and how do I know which role my organization plays?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        A deployer is an organization that deploys an existing AI system under its own responsibility, without fundamentally altering the system. You become a provider as soon as you make significant modifications to the system, assign it a new purpose, or associate your own name or brand with it. This distinction is crucial: as a provider, you are responsible for technical documentation, conformity assessment, and CE marking\u2014obligations that are significantly more onerous than those of a deployer. Are you unsure about your role? Have a legal or technical expert assess the situation before you further modify or roll out the system.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Does my chatbot also have to comply with the GDPR in addition to the AI Act, and how do I combine the two?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, the AI Act and the GDPR apply concurrently and complement each other. If your chatbot processes personal data, such as names, email addresses, or customer history, you are also subject to the GDPR obligations, including conducting a Data Protection Impact Assessment (DPIA). In practice, you can efficiently combine both by directly incorporating privacy risks into the risk analysis for the AI Act. A combined approach saves time and ensures a consistent governance structure within your organization.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I know if my chatbot is accidentally classified as high-risk?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The two main triggers for a high-risk classification are: profiling individual customers, and supporting decisions regarding access to essential services such as credit, insurance, or emergency calls. Carefully review what data your chatbot collects and analyzes, and what actions or recommendations it generates based on that data. For example, if your chatbot segments customers based on behavior and, as a result, displays different offers or refers them to services with significant financial or personal consequences, a high-risk assessment is necessary. If you\u2019re unsure, it\u2019s wise to have this assessed by an expert.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What exactly should be included in an internal AI registry, and how do I get started?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        An internal AI registry must contain at a minimum: a description of each AI system you use, its purpose and function, your role (deployer or provider), the risk level, the employee responsible for oversight, the retention period for logs, and the relevant compliance deadlines. Start simply with a structured spreadsheet or an existing GRC (Governance, Risk &amp; Compliance) tool that your organization already uses. The register doesn\u2019t have to be perfect on day one; the important thing is to maintain a living document that you can present to regulators and that provides clarity internally regarding responsibilities.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Does the transparency requirement also apply if my chatbot has a human name or avatar?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, in fact, the transparency requirement is even more relevant in that case. If your chatbot has a human name, such as \u2018Lisa\u2019 or \u2018Tom,\u2019 or a realistic human avatar, there is a risk that users will think they are communicating with a real employee. The AI Act requires that the AI\u2019s identity be clearly and promptly disclosed, regardless of the chatbot\u2019s form of presentation. A human name or avatar therefore does not exempt you from the disclosure requirement; in fact, it makes an explicit disclosure at the start of the conversation even more important.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What are the most common mistakes organizations make when preparing for AI Act compliance?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The most common mistakes are: implementing the transparency requirement too late or too vaguely (for example, only in the terms and conditions), underestimating when a modification to an existing system makes you a legal provider, and the lack of demonstrable human oversight. In addition, many organizations overlook the six-month log retention requirement or fail to inform employees in a timely manner about the use of AI systems. A proactive approach\u2014in which you document and internally communicate your compliance steps\u2014prevents most of these pitfalls.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I keep my AI Act compliance up to date as regulations or my chatbot continue to evolve?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        AI Act compliance is not a one-time exercise, but an ongoing process. Establish a fixed review cycle\u2014for example, every six months\u2014to check whether your chatbot\u2019s functionality has changed, whether new guidelines have been published by the European AI Office, and whether the compliance deadlines for your systems have shifted. Designate an internal point person, such as an AI coordinator or compliance officer, to track changes and keep the AI register up to date. Also, subscribe to updates from the relevant national regulator so that you are promptly informed of new enforcement developments in the Netherlands.                    <\/p>\n                <\/div>\n                        <\/div>\n        ","protected":false},"excerpt":{"rendered":"<p>The AI Act imposes specific obligations on chatbots \u2014 find out which rules already apply to your customer service.<\/p>\n","protected":false},"author":2,"featured_media":32837,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32836","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32836","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32836"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32836\/revisions"}],"predecessor-version":[{"id":32839,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32836\/revisions\/32839"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32837"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32836"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32836"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32836"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}