{"id":32848,"date":"2026-07-26T08:00:00","date_gmt":"2026-07-26T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-prepare-your-contact-center-for-the-ai-act\/"},"modified":"2026-07-26T10:00:45","modified_gmt":"2026-07-26T08:00:45","slug":"how-do-you-prepare-your-contact-center-for-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-prepare-your-contact-center-for-the-ai-act\/","title":{"rendered":"How do you prepare your contact center for the AI Act?"},"content":{"rendered":"<p>Preparing your contact center for the AI Act means, in practical terms: knowing which AI applications you use, determining whether they are classified as high-risk, and ensuring that you comply with the associated documentation, transparency, and oversight obligations. The law is already in effect, and most obligations for high-risk systems will become enforceable on August 2, 2026. In this article, we answer the most frequently asked questions about the AI Act and what it means for your <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">contact center technology<\/a>.  <\/p>\n<h2>Which AI applications in contact centers are covered by the AI Act?<\/h2>\n<p>Most AI applications in contact centers fall under the \u201climited risk\u201d or \u201cminimal risk\u201d categories, but a number of specific applications may be classified as \u201chigh risk.\u201d These include systems that profile customers, make decisions regarding access to services, or process biometric data. Chatbots and virtual assistants are generally subject to less stringent transparency requirements.  <\/p>\n<p>Specifically, these are the applications you should evaluate critically:<\/p>\n<ul>\n<li><strong>Automated customer profiling:<\/strong> Systems that create categories based on customer behavior or characteristics and use those categories to guide decisions are always high-risk whenever they profile natural persons.<\/li>\n<li><strong>Voice recognition and biometric identification:<\/strong> Voice-based authentication or emotion recognition via voice may be subject to strict restrictions, especially when it comes to emotion recognition in the workplace or in customer interactions.<\/li>\n<li><strong>Automated decisions regarding service provision:<\/strong> AI that determines whether a customer is eligible for a service, is given priority, or is transferred based on risk scores may fall under Annex III (access to essential services).<\/li>\n<li><strong>Chatbots and virtual agents:<\/strong> These are subject to transparency requirements. Customers must be informed that they are communicating with an AI system. <\/li>\n<li><strong>Quality Monitoring Using AI:<\/strong> Systems that automatically analyze conversations and evaluate employees may be classified as high-risk in the area of employment and human resources management.<\/li>\n<\/ul>\n<p>The key rule is that any system that profiles natural persons is automatically considered high-risk. If you\u2019re unsure whether an application in your contact center falls under this category, it\u2019s wise to have it reviewed by legal counsel before the enforcement deadlines expire.  <\/p>\n<h2>What are the specific requirements for high-risk AI systems?<\/h2>\n<p>High-risk AI systems are subject to extensive obligations that depend on your role: are you a provider (you develop or market the system) or a deployer (you use a system provided by another party)? Providers bear the greatest responsibility, but as a deployer, you also have specific obligations. <\/p>\n<h3>Obligations as a Provider of High-Risk AI<\/h3>\n<p>If your organization develops or significantly modifies AI systems on its own, the following requirements apply:<\/p>\n<ul>\n<li>A continuous risk management system covering the entire system lifecycle<\/li>\n<li>Technical documentation in accordance with Annex IV of the regulation<\/li>\n<li>Automatic event logging (audit trail)<\/li>\n<li>A design that effectively enables human oversight<\/li>\n<li>Conformity Assessment, EU Declaration of Conformity, and CE Marking<\/li>\n<li>Registration in the EU database for high-risk systems<\/li>\n<\/ul>\n<h3>Obligations as a Deployer of High-Risk AI<\/h3>\n<p>Do you use AI systems from a vendor in your contact center? If so, you are a deployer, and the following obligations apply: <\/p>\n<ul>\n<li>Use the system only in accordance with the provider&#8217;s instructions for use<\/li>\n<li>Assign human supervision to qualified and trained employees<\/li>\n<li>Retain logs for at least six months<\/li>\n<li>Informing employees before the system is put into use (Article 26(7))<\/li>\n<li>Conduct a data protection impact assessment (DPIA) where applicable<\/li>\n<\/ul>\n<p>An important point to note: a deployer can become a provider without realizing it. This happens when you make substantial modifications to a system, attach your own name to it, or alter its intended purpose in such a way that the system becomes high-risk. In that case, all provider obligations apply to your organization.  <\/p>\n<h2>When will the AI Act take effect, and what are the deadlines?<\/h2>\n<p>The AI Act is already in effect. The law took effect on August 1, 2024, but the requirements are being phased in. For contact centers, there are three key dates to keep in mind.  <\/p>\n<ul>\n<li><strong>February 2, 2025 (already passed):<\/strong> The prohibited practices outlined in Article 5 are in effect, as is the requirement for AI literacy. Your employees must understand how the AI systems they use work. <\/li>\n<li><strong>August 2, 2025 (already passed):<\/strong> The requirements for General Purpose AI (GPAI) models have taken effect. Penalty provisions are in force, and national supervisory authorities must have been designated. <\/li>\n<li><strong>August 2, 2026:<\/strong> Most requirements for high-risk Annex III systems will become enforceable. This is the most relevant deadline for most contact centers. <\/li>\n<\/ul>\n<p>So, in 2026, there will still be limited time to prepare for the high-risk obligations. Start now by taking stock of your AI systems so that you\u2019ll know in time which category they fall into and what steps you still need to take. <\/p>\n<h2>How do you conduct an AI risk assessment for your contact center?<\/h2>\n<p>To conduct an AI risk assessment for your contact center, you should systematically identify all AI systems, determine the risk category for each system, and then document the corresponding obligations. This doesn\u2019t have to be a complicated legal process if you take it step by step. <\/p>\n<p>Follow this approach:<\/p>\n<ol>\n<li><strong>Create an AI inventory:<\/strong> Document all the AI systems you use, including the less obvious ones, such as automated routing algorithms, sentiment analysis, or AI-generated call summaries.<\/li>\n<li><strong>Determine your role:<\/strong> Are you a provider, deployer, importer, or distributor? Also check to see if you\u2019ve inadvertently become a provider as a result of changes to existing systems. <\/li>\n<li><strong>Classify the risk:<\/strong> Assess each system against the prohibited practices (Article 5), the high-risk criteria (Article 6 and Annex III), and the transparency requirements for limited risk.<\/li>\n<li><strong>Check for profiling:<\/strong> Any system that profiles individuals is automatically considered high-risk. This is a strict rule with no exceptions. <\/li>\n<li><strong>Document your reasoning:<\/strong> If you conclude that an Annex III system does not pose a significant risk to fundamental rights, you must document this conclusion with supporting evidence. Verbal agreements are insufficient. <\/li>\n<li><strong>Involve your suppliers:<\/strong> Actively ask AI system providers for their compliance status, technical documentation, and user manuals. As the deployer, you are entitled to this information. <\/li>\n<\/ol>\n<p>Document the results of this assessment in writing. In the event of an inspection by the regulatory authority, this documentation will serve as your primary evidence of compliance. <\/p>\n<h2>What are the penalties for noncompliance with the AI Act?<\/h2>\n<p>The fines for noncompliance with the AI Act are substantial and are divided into three tiers, depending on the severity of the violation. The provisions regarding fines will take effect on August 2, 2025. For SMEs, the lower of the percentage or the fixed amount applies in each case.  <\/p>\n<ul>\n<li><strong>Violations of prohibited practices (Article 5):<\/strong> Up to 35 million euros or 7% of global annual revenue, whichever is higher. These are the most serious violations, such as the use of manipulative AI or unauthorized biometric identification. <\/li>\n<li><strong>Non-compliance with other obligations:<\/strong> Up to 15 million euros or 3% of global annual revenue. This applies to non-compliance with documentation, logging, or monitoring requirements for high-risk systems. <\/li>\n<li><strong>Inaccurate or misleading information provided to authorities:<\/strong> Up to 7.5 million euros or 1% of global annual revenue.<\/li>\n<\/ul>\n<p>In January 2026, Finland became the first member state to formally grant enforcement powers to its regulatory authority. Other EU member states are expected to follow suit soon. So don\u2019t wait until enforcement begins, because the obligations are already in effect.  <\/p>\n<h2>How do you ensure transparency for customers when using AI?<\/h2>\n<p>Transparency toward customers regarding the use of AI is required as soon as customers come into contact with an AI system that is not immediately recognizable as such. The basic rule: customers must always know that they are interacting with an AI system, unless this is self-evident to a reasonable person. <\/p>\n<p>Practical steps for transparency in your contact center:<\/p>\n<ul>\n<li><strong>Identify your chatbot or virtual assistant:<\/strong> Clearly state at the beginning of a conversation that the customer is speaking with an AI. This applies to chat as well as automated phone calls. <\/li>\n<li><strong>Offer a human alternative:<\/strong> Customers should always have the option to be connected to a human representative if they wish.<\/li>\n<li><strong>Provide information about automated decisions:<\/strong> If AI influences a decision that affects a customer, that customer has the right, under Article 86, to an explanation of the determining factors.<\/li>\n<li><strong>Update your privacy policy:<\/strong> Explain which AI systems you use, what data is processed for those purposes, and how long you retain your logs.<\/li>\n<li><strong>Train your employees:<\/strong> The AI literacy requirement is already in effect. Employees who work with AI systems must understand how those systems work and what their limitations are. <\/li>\n<\/ul>\n<p>Transparency isn&#8217;t just a legal requirement\u2014it&#8217;s also an opportunity. Customers appreciate honesty about the use of AI, especially when you show them that the technology helps them faster and more effectively, rather than sending them through a maze of menus. <\/p>\n<h2>How Pegamento Helps Ensure AI Act Compliance in Your Contact Center<\/h2>\n<p>The AI Act requires a comprehensive approach to your contact center technology: from assessing your systems to establishing human oversight and ensuring transparency. We assist Dutch organizations at every step of this process, serving as a single point of contact for the entire solution. No silos, no complex coordination between multiple vendors.  <\/p>\n<p>What we specifically do for you:<\/p>\n<ul>\n<li>Inventory of all AI applications in your contact center and classification by risk category<\/li>\n<li>Implementing logging, documentation, and human oversight in accordance with the requirements of the AI Act<\/li>\n<li>Implementing Transparent Customer Communication in AI-Driven Interactions<\/li>\n<li>Providing <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a>, built from the ground up with compliance in mind. Agentic AI represents the evolution from task-oriented bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently. <\/li>\n<li>Support in establishing an AI registry and conducting a DPIA where necessary<\/li>\n<li>Everything under one roof, including management and ongoing support, certified to ISO 27001, ISO 9001, and ISO 26000<\/li>\n<\/ul>\n<p>Would you like to know how your contact center is currently faring in terms of compliance with the AI Act requirements? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a> for a no-obligation consultation.<\/p>\n        <div class=\"wp-block-seoaic-faq-block\">\n            <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n                            <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Does the AI Act also apply to small contact centers, or only to large organizations?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The AI Act applies to all organizations that use or offer AI systems within the EU, regardless of their size. However, mitigating measures apply to SMEs: in the case of fines, the lower of the two amounts (the percentage or the fixed maximum) is always applied. Nevertheless, the core obligations\u2014such as maintaining an AI register, transparency toward customers, and human oversight\u2014are also mandatory for smaller contact centers. Smaller organizations would be wise to start with a simple inventory of their AI applications so they know where they stand in a timely manner.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What should I do if my AI vendor cannot provide compliance documentation?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        As a deployer, you have a legal right to the technical documentation and user manual from the provider of a high-risk AI system. If your supplier is unable or unwilling to provide these, that poses a serious risk: as the deployer, you are jointly responsible for the correct use of the system. Issue a written notice of default to your supplier and document this. Also consider whether it is prudent to continue using this system until the supplier is demonstrably compliant, because in the event of an inspection by the regulatory authority, your own documentation will be your primary evidence.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I know if my AI quality monitoring system is classified as high-risk?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        AI systems that automatically analyze conversations and evaluate employees potentially fall under the 'employment and workforce management' domain in Annex III of the AI Act, which implies high risk. The key question is whether the system is used to make or significantly influence decisions that affect employees, such as performance evaluations, promotions, or terminations. If the system is used purely for informational purposes without directly impacting decision-making, it may fall outside the high-risk category\u2014but you must document this with supporting evidence. If in doubt, consult a legal advisor specializing in AI regulations.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What is the difference between the AI Act and the GDPR, and do I need to comply with both?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, both pieces of legislation apply and complement each other. The GDPR governs the protection of personal data during processing, while the AI Act specifically addresses the risks posed by AI systems themselves, such as transparency, human oversight, and technical robustness. In practice, they often overlap: a high-risk AI system that processes personal data requires both a DPIA (GDPR) and technical documentation and logging (AI Act). Treat compliance with both regulations as a single integrated process to avoid duplication of effort.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I implement human oversight without undermining the efficiency of my contact center?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Human oversight does not necessarily mean that an employee manually checks every AI decision. The AI Act requires that oversight be effective and feasible: employees must understand how the system works, be able to intervene when necessary, and be able to override or shut down the system. In practice, you can implement this through random checks, escalation protocols for cases of doubt, and clear thresholds at which an AI decision is automatically forwarded to a human. Make sure this procedure is documented in writing as part of your compliance documentation.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What should I include in my AI register to comply with the AI Act?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        An AI register for your contact center must include at a minimum: the name and description of each AI system, the vendor, and your role (provider or deployer), the risk category with justification, the purposes for which the system is used, what personal data is processed, how human oversight is organized, and where logs are stored. For high-risk systems, you must also document the provider\u2019s compliance status. The register doesn\u2019t have to be complex, but it must remain up to date: update it immediately whenever there\u2019s a change in your AI landscape.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What are the most common mistakes contact centers make when preparing for the AI Act?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The most common mistakes are: starting the inventory of AI systems too late, assuming that only in-house AI systems are covered by the law (purchased systems also count), and underestimating the deployer\u2019s role by placing all responsibility on the supplier. Another common mistake is failing to inform employees about the AI systems they use, even though the AI literacy requirement has been in effect since February 2025. Start with an honest inventory of all AI applications in your contact center\u2014including the less visible ones, such as routing algorithms or automated summaries\u2014and document everything in writing.                    <\/p>\n                <\/div>\n                        <\/div>\n        ","protected":false},"excerpt":{"rendered":"<p>The AI Act is already in effect\u2014do you know which contact center systems are considered high-risk before August 2026?<\/p>\n","protected":false},"author":2,"featured_media":32849,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32848","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32848"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848\/revisions"}],"predecessor-version":[{"id":32851,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32848\/revisions\/32851"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32849"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}