{"id":33152,"date":"2026-07-28T08:00:00","date_gmt":"2026-07-28T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-can-you-ensure-that-rpa-and-ai-automation-comply-with-the-ai-act\/"},"modified":"2026-07-28T10:00:43","modified_gmt":"2026-07-28T08:00:43","slug":"how-can-you-ensure-that-rpa-and-ai-automation-comply-with-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-can-you-ensure-that-rpa-and-ai-automation-comply-with-the-ai-act\/","title":{"rendered":"How can you ensure that RPA and AI automation comply with the AI Act?"},"content":{"rendered":"<p>RPA and AI automation comply with the AI Act when you correctly classify the systems you use based on risk, comply with the associated obligations, and clearly assign responsibilities between the supplier and the user. For most <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">AI-driven process automation<\/a> in business environments, the systems fall into the \u201cminimal\u201d or \u201climited\u201d risk categories, for which the requirements are significantly less stringent than for high-risk applications. In this article, we answer the most frequently asked questions about the AI Act, specifically focused on organizations that work with RPA, Agentic AI, and process automation.  <\/p>\n<h2>Which AI systems are covered by the AI Act?<\/h2>\n<p>The AI Act applies to any AI system offered or deployed in the European Union, regardless of where the provider is established. Specifically, a system falls under the scope of the law if it contains a machine learning component, rule-based reasoning, or a statistical model that generates output, such as predictions, recommendations, decisions, or generated content. <\/p>\n<p>For process automation, this means that traditional rule-based RPA bots fall into a gray area. Purely deterministic scripts that execute fixed instructions step by step without any inference or learning component are generally not considered AI systems under the law. However, as soon as an automation solution uses machine learning, natural language processing, computer vision, or self-learning models to make decisions, the system does fall under the AI Act.  <\/p>\n<p>Agentic AI systems\u2014which independently plan and execute tasks based on context and objectives\u2014almost always fall under the definition. The same applies to chatbots that respond based on language models, AI-driven routing systems in contact centers, and computer vision applications that interpret images. In short: the more a system reasons autonomously, the more certain it is that the AI Act applies.  <\/p>\n<h2>How does the AI Act&#8217;s risk classification work?<\/h2>\n<p>The AI Act classifies AI systems into four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (minimal transparency requirements), and minimal risk (unregulated). The vast majority of business AI applications fall into the minimal or limited-risk categories. <\/p>\n<p>The four levels work as follows:<\/p>\n<ul>\n<li><strong>Unacceptable risk:<\/strong> Prohibited practices such as manipulative techniques, social scoring by governments, real-time biometric identification in public spaces, and emotion recognition in the workplace. These prohibitions will take effect as of February 2, 2025. <\/li>\n<li><strong>High risk:<\/strong> Systems used in eight specific areas, such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice. Systems that create profiles of individuals are also always considered high risk. <\/li>\n<li><strong>Limited risk:<\/strong> Systems such as chatbots and deepfakes where users must be aware that they are interacting with AI. The primary requirement is transparency. <\/li>\n<li><strong>Minimal risk:<\/strong> Spam filters, AI in video games, and similar applications. No specific obligations. <\/li>\n<\/ul>\n<p>With regard to process automation in business environments, most applications fall into the \u201cminimal\u201d or \u201climited\u201d risk categories, unless they are used in one of the eight high-risk domains or perform personal profiling.<\/p>\n<h2>What are the requirements for high-risk AI systems?<\/h2>\n<p>High-risk AI systems are subject to a comprehensive set of obligations that apply to both providers and users. The core obligations revolve around documentation, transparency, human oversight, and quality assurance of data and processes. <\/p>\n<p>The main obligations for providers of high-risk AI are:<\/p>\n<ul>\n<li>Establishing and maintaining a robust quality management system<\/li>\n<li>Prepare technical documentation demonstrating that the system meets the requirements<\/li>\n<li>Implement automatic activity logging to ensure the system is traceable<\/li>\n<li>Provide transparent user information about capabilities and limitations<\/li>\n<li>Enable human oversight so that an employee can adjust or stop the system<\/li>\n<li>Ensuring robustness, accuracy, and cybersecurity<\/li>\n<li>Conduct a conformity assessment and affix the CE marking<\/li>\n<li>Register the system in the EU database for high-risk AI<\/li>\n<\/ul>\n<p>Users (deployers) of high-risk AI are subject to additional obligations: they must use the system in accordance with the provider\u2019s instructions, organize human oversight, and, when using the system in HR decisions or in the provision of services to citizens, conduct a fundamental rights impact assessment. Users are also required to report incidents and train employees in AI literacy, a requirement that will take effect as of February 2, 2025. <\/p>\n<h2>How do you determine whether an RPA process is high-risk or not?<\/h2>\n<p>To determine whether an RPA process is high-risk, ask yourself two questions: Does the system fall under Annex I (safety component in regulated products) or Annex III (one of the eight high-risk usage scenarios)? If the answer to both questions is no, the system is not a high-risk system in most cases. <\/p>\n<p>For each automation process, follow these steps:<\/p>\n<ol>\n<li><strong>Determine whether the system incorporates AI:<\/strong> Does it use machine learning, NLP, or computer vision? If not, then it falls outside the scope of the AI Act. <\/li>\n<li><strong>Check the Annex III areas:<\/strong> Is the system used for HR decisions (hiring, promotion, termination), creditworthiness assessments, access to government benefits, or other areas within the eight categories?<\/li>\n<li><strong>Check for personal profiling:<\/strong> Does the system create profiles of individuals based on personal data? If so, it is always considered high risk. <\/li>\n<li><strong>Assess the impact on fundamental rights:<\/strong> Can the system make decisions that have significant consequences for people? This is an indication of high risk. <\/li>\n<li><strong>Document your conclusion:<\/strong> Even if you conclude that the system is not high-risk, you should document your reasoning in writing. This will protect you in the event of an audit. <\/li>\n<\/ol>\n<p>A practical example: An RPA bot that processes invoices and prepares payments for approval is, in most cases, not a high-risk system. An AI system that evaluates resumes and ranks candidates for hiring processes does fall into the high-risk category, however, because it falls under employment and human resources management. <\/p>\n<h2>Who is responsible for compliance with the AI Act: the supplier or the user?<\/h2>\n<p>Both the provider and the user (deployer) bear responsibility, but for different obligations. The provider is primarily responsible for the system\u2019s technical compliance. The user is responsible for the proper deployment of the system within their own organization and context.  <\/p>\n<p>The division of responsibilities is as follows:<\/p>\n<ul>\n<li><strong>Provider:<\/strong> Conformity assessment, technical documentation, CE marking, registration in the EU database, post-market monitoring, and reporting of incidents to authorities.<\/li>\n<li><strong>User:<\/strong> Use the system in accordance with the instructions, ensure human supervision, train staff, conduct a fundamental rights impact assessment where required, and report incidents to the provider.<\/li>\n<\/ul>\n<p>There is one important point to note: a user can become a provider themselves, with all the associated obligations. This occurs when you put your own name on a system, make a substantial change to an existing system, or modify the intended purpose in such a way that a system falls into the high-risk category. Organizations that modify or combine AI systems from suppliers must pay close attention to this.  <\/p>\n<p>In addition, suppliers outside the EU must appoint an authorized representative in the EU. Importers and distributors also have their own verification obligations before they place a system on the market or distribute it. <\/p>\n<h2>When will the AI Act take effect, and what are the deadlines?<\/h2>\n<p>The AI Act will take effect in phases. The first requirements took effect on February 2, 2025. Most requirements for high-risk AI systems will take effect on August 2, 2026, which is the most relevant deadline for many organizations in terms of their process automation.  <\/p>\n<p>The complete timeline at a glance:<\/p>\n<ul>\n<li><strong>February 2, 2025:<\/strong> Prohibited practices (Article 5) are in effect. The requirement for employees to be AI-literate applies. <\/li>\n<li><strong>August 2, 2025:<\/strong> Requirements for GPAI models (such as large language models), the governance structure, national supervisory authorities, and the provisions on fines take effect.<\/li>\n<li><strong>August 2, 2026:<\/strong> Most requirements for high-risk Annex III systems will be fully in effect. This is the critical deadline for most business AI applications. <\/li>\n<li><strong>August 2, 2027:<\/strong> Requirements for high-risk AI used as a safety component in regulated products (Annex I) take effect. GPAI models that were already on the market before August 2025 must be compliant by that date at the latest. <\/li>\n<\/ul>\n<p>The fines are substantial: violations of the prohibited practices can result in fines of up to 35 million euros or 7% of global annual revenue. Non-compliance with other obligations can result in fines of up to 15 million euros or 3%. For SMEs, the lower of the percentage or the fixed amount applies in each case.  <\/p>\n<p>Given the August 2026 deadline, it is wise to start right away by taking stock of your AI systems, conducting a risk classification, and identifying the necessary documentation.<\/p>\n<h2>How Pegamento Helps with AI Act-Compliant Process Automation<\/h2>\n<p>If you work with process automation and AI, you want to be sure that your solutions comply with the AI Act without compromising your organization\u2019s efficiency or flexibility. We help organizations use AI and automation responsibly, from risk classification to implementation. <\/p>\n<p>What we specifically offer:<\/p>\n<ul>\n<li><strong>Agentic AI assistants<\/strong> that don\u2019t just follow instructions, but take the initiative and act on their own. This is what we mean by Agentic AI: an evolution from executive bots to self-thinking assistants that actively drive processes. Learn more about our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a>.  <\/li>\n<li><strong>Customized solutions using standard building blocks<\/strong>\u2014not costly custom work, but a smart combination of proven modules that are perfectly tailored to your situation and industry.<\/li>\n<li><strong>Everything under one roof<\/strong>, from development and implementation to management and support, without complex supplier management or silos.<\/li>\n<li><strong>ISO 27001-certified information security<\/strong>, supplemented by ISO 9001 and ISO 26000, ensuring that compliance and quality are structurally guaranteed.<\/li>\n<li><strong>Guidance on preparing for the AI Act<\/strong>, including assistance with risk classification, documentation, and establishing human oversight of automated processes.<\/li>\n<\/ul>\n<p>Would you like to know how your current or planned automation solutions align with the AI Act? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019ll work with you to determine the best approach for your organization.<\/p>\n        <div class=\"wp-block-seoaic-faq-block\">\n            <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n                            <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Do I need to perform a risk classification for each RPA bot individually, or can I do this on a per-process or per-department basis?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        It is advisable to perform the risk classification at the system level\u2014that is, for each individual automation solution that contains a separate AI component. You can group bots that use the same technology for similar tasks into a classification template, but as soon as the usage context or domain differs, you must repeat the classification. An invoice processing bot and an HR screening bot fall into completely different risk categories, even though they run on the same platform.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What specific steps do I need to take to comply with the AI literacy requirement that has been in effect since February 2, 2025?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The AI literacy requirement mandates that, as a user organization, you ensure employees who work with AI systems have sufficient knowledge to operate and evaluate these systems responsibly. In practical terms, this means: identify which employees use AI systems, develop a basic training program on the operation, limitations, and risks of the relevant systems, and document who completed which training and when. You don\u2019t need to turn your employees into AI experts, but you must be able to demonstrate that they use the AI tools they employ on a daily basis in a knowledgeable and competent manner.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What happens if I modify an AI system from a third-party provider for my own use\u2014does that make me a provider myself?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, in certain situations it does. Legally speaking, you become a provider if you make a substantial modification to an existing AI system, affix your own name or brand to the system, or alter the system\u2019s intended purpose in such a way that it falls into a higher risk category. Practical example: If you reconfigure a vendor\u2019s standard language model to independently support HR decisions, you are no longer just a user but also a provider, with all the associated obligations such as conformity assessment and technical documentation. Always specify contractually who bears which responsibilities.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I implement &#039;human oversight&#039; of an automated AI process in practice?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Human oversight does not mean that an employee must manually check every decision made by an AI system, but it does mean that there is a functioning mechanism in place to intervene when necessary. Specifically, this could include: an approval workflow for decisions above a certain threshold, a dashboard where deviations or exceptions are visible to a responsible employee, and a clearly documented procedure for pausing or stopping the system. Also ensure that the employee responsible for oversight has sufficient context and authority to actually make adjustments\u2014oversight on paper without real leeway to act doesn\u2019t count.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Does the AI Act also apply to AI systems that we use internally and do not offer to customers?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, the AI Act makes no distinction between internal use and external provision. As soon as you deploy an AI system within the EU\u2014even purely for internal processes such as HR, finance, or operations\u2014you, as the user organization, are bound by the obligations that apply to deployers. If you developed the system yourself and use it internally, you are both a provider and a user, and both sets of obligations apply. Internal AI tools that perform high-risk tasks, such as automated employee evaluations, are therefore fully subject to the law.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What is the biggest practical risk if I don\u2019t take any action now to prepare for the AI Act?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The biggest risk isn\u2019t so much the immediate fine, but the operational disruption if you discover just before the August 2026 deadline that one or more of your AI systems are high-risk and do not yet meet the documentation and oversight requirements. Setting up a quality management system, drafting technical documentation, and organizing human oversight after the fact takes considerably more time and money than if you incorporate these steps into your regular development and implementation cycle. Therefore, start now by conducting an inventory of your AI systems, even if you suspect that most fall into the low-risk categories.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Are there specific sectors or use cases within process automation where the likelihood of a high-risk classification is particularly high?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, the likelihood of a high-risk classification is significantly higher in sectors and use cases that directly impact human rights, access to services, or employment. Examples include: automated credit assessments or fraud detection at financial institutions, AI-driven recruitment and selection tools in HR, automated triage or prioritization in healthcare, and systems that determine whether someone is eligible for government benefits or services. Contact center automation, in which AI determines how customers are routed or assessed, can also fall into the high-risk category when it comes to access to essential services. A sector review is therefore always part of a proper risk classification.                    <\/p>\n                <\/div>\n                        <\/div>\n        ","protected":false},"excerpt":{"rendered":"<p>The AI Act also applies to RPA and Agentic AI \u2014 find out how risk classification can protect your organization before the 2026 deadline.<\/p>\n","protected":false},"author":2,"featured_media":33153,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-33152","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=33152"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33152\/revisions"}],"predecessor-version":[{"id":33155,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33152\/revisions\/33155"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/33153"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=33152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=33152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=33152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}