{"id":32848,"date":"2026-07-26T08:00:00","date_gmt":"2026-07-26T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-prepare-your-contact-center-for-the-ai-act\/"},"modified":"2026-07-26T10:00:45","modified_gmt":"2026-07-26T08:00:45","slug":"how-do-you-prepare-your-contact-center-for-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-prepare-your-contact-center-for-the-ai-act\/","title":{"rendered":"How do you prepare your contact center for the AI Act?"},"content":{"rendered":"<p>Preparing your contact center for the AI Act means, in practical terms: knowing which AI applications you use, determining whether they are classified as high-risk, and ensuring that you comply with the associated documentation, transparency, and oversight obligations. The law is already in effect, and most obligations for high-risk systems will become enforceable on August 2, 2026. In this article, we answer the most frequently asked questions about the AI Act and what it means for your <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">contact center technology<\/a>.  <\/p>\n<h2>Which AI applications in contact centers are covered by the AI Act?<\/h2>\n<p>Most AI applications in contact centers fall under the \u201climited risk\u201d or \u201cminimal risk\u201d categories, but a number of specific applications may be classified as \u201chigh risk.\u201d These include systems that profile customers, make decisions regarding access to services, or process biometric data. Chatbots and virtual assistants are generally subject to less stringent transparency requirements.  <\/p>\n<p>Specifically, these are the applications you should evaluate critically:<\/p>\n<ul>\n<li><strong>Automated customer profiling:<\/strong> Systems that create categories based on customer behavior or characteristics and use those categories to guide decisions are always high-risk whenever they profile natural persons.<\/li>\n<li><strong>Voice recognition and biometric identification:<\/strong> Voice-based authentication or emotion recognition via voice may be subject to strict restrictions, especially when it comes to emotion recognition in the workplace or in customer interactions.<\/li>\n<li><strong>Automated decisions regarding service provision:<\/strong> AI that determines whether a customer is eligible for a service, is given priority, or is transferred based on risk scores may fall under Annex III (access to essential services).<\/li>\n<li><strong>Chatbots and virtual agents:<\/strong> These are subject to transparency requirements. Customers must be informed that they are communicating with an AI system. <\/li>\n<li><strong>Quality Monitoring Using AI:<\/strong> Systems that automatically analyze conversations and evaluate employees may be classified as high-risk in the area of employment and human resources management.<\/li>\n<\/ul>\n<p>The key rule is that any system that profiles natural persons is automatically considered high-risk. If you\u2019re unsure whether an application in your contact center falls under this category, it\u2019s wise to have it reviewed by legal counsel before the enforcement deadlines expire.  <\/p>\n<h2>What are the specific requirements for high-risk AI systems?<\/h2>\n<p>High-risk AI systems are subject to extensive obligations that depend on your role: are you a provider (you develop or market the system) or a deployer (you use a system provided by another party)? Providers bear the greatest responsibility, but as a deployer, you also have specific obligations. <\/p>\n<h3>Obligations as a Provider of High-Risk AI<\/h3>\n<p>If your organization develops or significantly modifies AI systems on its own, the following requirements apply:<\/p>\n<ul>\n<li>A continuous risk management system covering the entire system lifecycle<\/li>\n<li>Technical documentation in accordance with Annex IV of the regulation<\/li>\n<li>Automatic event logging (audit trail)<\/li>\n<li>A design that effectively enables human oversight<\/li>\n<li>Conformity Assessment, EU Declaration of Conformity, and CE Marking<\/li>\n<li>Registration in the EU database for high-risk systems<\/li>\n<\/ul>\n<h3>Obligations as a Deployer of High-Risk AI<\/h3>\n<p>Do you use AI systems from a vendor in your contact center? If so, you are a deployer, and the following obligations apply: <\/p>\n<ul>\n<li>Use the system only in accordance with the provider&#8217;s instructions for use<\/li>\n<li>Assign human supervision to qualified and trained employees<\/li>\n<li>Retain logs for at least six months<\/li>\n<li>Informing employees before the system is put into use (Article 26(7))<\/li>\n<li>Conduct a data protection impact assessment (DPIA) where applicable<\/li>\n<\/ul>\n<p>An important point to note: a deployer can become a provider without realizing it. This happens when you make substantial modifications to a system, attach your own name to it, or alter its intended purpose in such a way that the system becomes high-risk. In that case, all provider obligations apply to your organization.  <\/p>\n<h2>When will the AI Act take effect, and what are the deadlines?<\/h2>\n<p>The AI Act is already in effect. The law took effect on August 1, 2024, but the requirements are being phased in. For contact centers, there are three key dates to keep in mind.  <\/p>\n<ul>\n<li><strong>February 2, 2025 (already passed):<\/strong> The prohibited practices outlined in Article 5 are in effect, as is the requirement for AI literacy. Your employees must understand how the AI systems they use work. <\/li>\n<li><strong>August 2, 2025 (already passed):<\/strong> The requirements for General Purpose AI (GPAI) models have taken effect. Penalty provisions are in force, and national supervisory authorities must have been designated. <\/li>\n<li><strong>August 2, 2026:<\/strong> Most requirements for high-risk Annex III systems will become enforceable. This is the most relevant deadline for most contact centers. <\/li>\n<\/ul>\n<p>So, in 2026, there will still be limited time to prepare for the high-risk obligations. Start now by taking stock of your AI systems so that you\u2019ll know in time which category they fall into and what steps you still need to take. <\/p>\n<h2>How do you conduct an AI risk assessment for your contact center?<\/h2>\n<p>To conduct an AI risk assessment for your contact center, you should systematically identify all AI systems, determine the risk category for each system, and then document the corresponding obligations. This doesn\u2019t have to be a complicated legal process if you take it step by step. <\/p>\n<p>Follow this approach:<\/p>\n<ol>\n<li><strong>Create an AI inventory:<\/strong> Document all the AI systems you use, including the less obvious ones, such as automated routing algorithms, sentiment analysis, or AI-generated call summaries.<\/li>\n<li><strong>Determine your role:<\/strong> Are you a provider, deployer, importer, or distributor? Also check to see if you\u2019ve inadvertently become a provider as a result of changes to existing systems. <\/li>\n<li><strong>Classify the risk:<\/strong> Assess each system against the prohibited practices (Article 5), the high-risk criteria (Article 6 and Annex III), and the transparency requirements for limited risk.<\/li>\n<li><strong>Check for profiling:<\/strong> Any system that profiles individuals is automatically considered high-risk. This is a strict rule with no exceptions. <\/li>\n<li><strong>Document your reasoning:<\/strong> If you conclude that an Annex III system does not pose a significant risk to fundamental rights, you must document this conclusion with supporting evidence. Verbal agreements are insufficient. <\/li>\n<li><strong>Involve your suppliers:<\/strong> Actively ask AI system providers for their compliance status, technical documentation, and user manuals. As the deployer, you are entitled to this information. <\/li>\n<\/ol>\n<p>Document the results of this assessment in writing. In the event of an inspection by the regulatory authority, this documentation will serve as your primary evidence of compliance. <\/p>\n<h2>What are the penalties for noncompliance with the AI Act?<\/h2>\n<p>The fines for noncompliance with the AI Act are substantial and are divided into three tiers, depending on the severity of the violation. The provisions regarding fines will take effect on August 2, 2025. For SMEs, the lower of the percentage or the fixed amount applies in each case.  <\/p>\n<ul>\n<li><strong>Violations of prohibited practices (Article 5):<\/strong> Up to 35 million euros or 7% of global annual revenue, whichever is higher. These are the most serious violations, such as the use of manipulative AI or unauthorized biometric identification. <\/li>\n<li><strong>Non-compliance with other obligations:<\/strong> Up to 15 million euros or 3% of global annual revenue. This applies to non-compliance with documentation, logging, or monitoring requirements for high-risk systems. <\/li>\n<li><strong>Inaccurate or misleading information provided to authorities:<\/strong> Up to 7.5 million euros or 1% of global annual revenue.<\/li>\n<\/ul>\n<p>In January 2026, Finland became the first member state to formally grant enforcement powers to its regulatory authority. Other EU member states are expected to follow suit soon. So don\u2019t wait until enforcement begins, because the obligations are already in effect.  <\/p>\n<h2>How do you ensure transparency for customers when using AI?<\/h2>\n<p>Transparency toward customers regarding the use of AI is required as soon as customers come into contact with an AI system that is not immediately recognizable as such. The basic rule: customers must always know that they are interacting with an AI system, unless this is self-evident to a reasonable person. <\/p>\n<p>Practical steps for transparency in your contact center:<\/p>\n<ul>\n<li><strong>Identify your chatbot or virtual assistant:<\/strong> Clearly state at the beginning of a conversation that the customer is speaking with an AI. This applies to chat as well as automated phone calls. <\/li>\n<li><strong>Offer a human alternative:<\/strong> Customers should always have the option to be connected to a human representative if they wish.<\/li>\n<li><strong>Provide information about automated decisions:<\/strong> If AI influences a decision that affects a customer, that customer has the right, under Article 86, to an explanation of the determining factors.<\/li>\n<li><strong>Update your privacy policy:<\/strong> Explain which AI systems you use, what data is processed for those purposes, and how long you retain your logs.<\/li>\n<li><strong>Train your employees:<\/strong> The AI literacy requirement is already in effect. Employees who work with AI systems must understand how those systems work and what their limitations are. <\/li>\n<\/ul>\n<p>Transparency isn&#8217;t just a legal requirement\u2014it&#8217;s also an opportunity. Customers appreciate honesty about the use of AI, especially when you show them that the technology helps them faster and more effectively, rather than sending them through a maze of menus. <\/p>\n<h2>How Pegamento Helps Ensure AI Act Compliance in Your Contact Center<\/h2>\n<p>The AI Act requires a comprehensive approach to your contact center technology: from assessing your systems to establishing human oversight and ensuring transparency. We assist Dutch organizations at every step of this process, serving as a single point of contact for the entire solution. No silos, no complex coordination between multiple vendors.  <\/p>\n<p>What we specifically do for you:<\/p>\n<ul>\n<li>Inventory of all AI applications in your contact center and classification by risk category<\/li>\n<li>Implementing logging, documentation, and human oversight in accordance with the requirements of the AI Act<\/li>\n<li>Implementing Transparent Customer Communication in AI-Driven Interactions<\/li>\n<li>Providing <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a>, built from the ground up with compliance in mind. Agentic AI represents the evolution from task-oriented bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently. <\/li>\n<li>Support in establishing an AI registry and conducting a DPIA where necessary<\/li>\n<li>Everything under one roof, including management and ongoing support, certified to ISO 27001, ISO 9001, and ISO 26000<\/li>\n<\/ul>\n<p>Would you like to know how your contact center is currently faring in terms of compliance with the AI Act requirements? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a> for a no-obligation consultation.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Geldt de AI Act ook voor kleine contactcenters of alleen voor grote organisaties?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act geldt voor alle organisaties die AI-systemen gebruiken of aanbieden binnen de EU, ongeacht hun omvang. Voor kmo&#8217;s gelden wel verzachtende maatregelen: bij boetes wordt telkens het laagste bedrag gehanteerd (het percentage of het vaste maximum). Toch zijn de kernverplichtingen \u2014 zoals het bijhouden van een AI-register, transparantie naar klanten en menselijk toezicht \u2014 ook voor kleinere contactcenters verplicht. Kleinere organisaties doen er goed aan te beginnen met een eenvoudige inventarisatie van hun AI-toepassingen, zodat ze tijdig weten waar ze aan toe zijn.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik doen als mijn AI-leverancier geen conformiteitsdocumentatie kan aanleveren?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Als deployer heb je wettelijk recht op de technische documentatie en gebruiksaanwijzing van de aanbieder van een hoog-risico AI-systeem. Kan of wil je leverancier deze niet aanleveren, dan is dat een serieus risico: jij bent als deployer mede verantwoordelijk voor correct gebruik van het systeem. Stel je leverancier schriftelijk in gebreke en documenteer dit. Overweeg ook of het verstandig is dit systeem te blijven gebruiken totdat de leverancier aantoonbaar compliant is, want bij een controle door de toezichthouder is jouw eigen documentatie je voornaamste bewijs.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe weet ik of mijn AI-kwaliteitsmonitoringsysteem als hoog-risico wordt geclassificeerd?            <\/h3>\n            <p class=\"seoaic-answer\">\n                AI-systemen die gesprekken automatisch analyseren en medewerkers beoordelen, vallen potentieel onder het domein &#8216;werkgelegenheid en personeelsbeheer&#8217; in Annex III van de AI Act, wat hoog-risico impliceert. De sleutelvraag is of het systeem wordt gebruikt om beslissingen te nemen of sterk te be\u00efnvloeden die gevolgen hebben voor medewerkers, zoals beoordeling, promotie of ontslag. Wordt het systeem puur informatief ingezet zonder directe beslissingsimpact, dan kan het buiten de hoog-risico categorie vallen \u2014 maar dit moet je onderbouwd vastleggen. Raadpleeg bij twijfel een juridisch adviseur gespecialiseerd in AI-regelgeving.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat is het verschil tussen de AI Act en de AVG, en moet ik aan beide voldoen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, beide wetgevingen zijn van toepassing en vullen elkaar aan. De AVG regelt de bescherming van persoonsgegevens bij verwerking, terwijl de AI Act specifiek gericht is op de risico&#8217;s van AI-systemen zelf, zoals transparantie, menselijk toezicht en technische robuustheid. In de praktijk overlappen ze regelmatig: een hoog-risico AI-systeem dat persoonsgegevens verwerkt, vereist zowel een DPIA (AVG) als technische documentatie en logging (AI Act). Behandel compliance voor beide regelingen als \u00e9\u00e9n ge\u00efntegreerd traject om dubbel werk te voorkomen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe richt ik menselijk toezicht in zonder dat dit de effici\u00ebntie van mijn contactcenter ondermijnt?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Menselijk toezicht hoeft niet te betekenen dat een medewerker elke AI-beslissing handmatig controleert. De AI Act vereist dat toezicht effectief en haalbaar is: medewerkers moeten de werking van het systeem begrijpen, kunnen ingrijpen wanneer nodig, en in staat zijn het systeem te overrulen of stop te zetten. Praktisch kun je dit inrichten via steekproefsgewijze controles, escalatieprotocollen bij twijfelgevallen en duidelijke drempelwaarden waarbij een AI-beslissing automatisch naar een mens wordt doorgestuurd. Zorg dat deze werkwijze schriftelijk is vastgelegd als onderdeel van je compliance-documentatie.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik opnemen in mijn AI-register om aan de AI Act te voldoen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een AI-register voor je contactcenter bevat minimaal: de naam en beschrijving van elk AI-systeem, de leverancier en jouw rol (aanbieder of deployer), de risicocategorie met onderbouwing, de doeleinden waarvoor het systeem wordt ingezet, welke persoonsgegevens worden verwerkt, hoe menselijk toezicht is georganiseerd, en waar logs worden bewaard. Voor hoog-risico systemen moet je ook de conformiteitsstatus van de aanbieder documenteren. Het register hoeft niet complex te zijn, maar moet actueel blijven: pas het bij elke wijziging in je AI-landschap direct aan.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat zijn de meest voorkomende fouten die contactcenters maken bij het voorbereiden op de AI Act?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De meest gemaakte fouten zijn: te laat beginnen met de inventarisatie van AI-systemen, ervan uitgaan dat alleen zelfgebouwde AI onder de wet valt (ook ingekochte systemen tellen mee), en de deployer-rol onderschatten door alle verantwoordelijkheid bij de leverancier te leggen. Een andere veelgemaakte fout is het niet informeren van medewerkers over de AI-systemen die ze gebruiken, terwijl de AI-geletterdheidsplicht al sinds februari 2025 van kracht is. Begin met een eerlijke inventarisatie van alle AI-toepassingen in je contactcenter \u2014 ook de minder zichtbare, zoals routeringsalgoritmen of geautomatiseerde samenvattingen \u2014 en leg alles schriftelijk vast.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The AI Act is already in effect\u2014do you know which contact center systems are considered high-risk before August 2026?<\/p>\n","protected":false},"author":2,"featured_media":32849,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32848","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32848"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848\/revisions"}],"predecessor-version":[{"id":32851,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848\/revisions\/32851"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32849"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}