The headlines in July said the EU AI Act had been delayed, and for the part they were describing, that was true. The Digital Omnibus came into force at the end of the month and moved the high-risk tier out to December 2027.
What got less attention is that the pieces which actually touch a support operation weren’t moved at all. Prohibited practices have applied since February 2025, and the transparency rules in Article 50 started on 2 August this year. Those are the ones that reach chatbots, QA tooling and the people working your queue.
If you’ve outsourced your support, the awkward part is that most of the exposure stays with you. You’re the deployer. There’s no automatic transfer of responsibility to whoever built the tool or whoever runs the team.
Which of your tools listen to my customers, and which listen to my agents?
Emotion recognition on employees has been prohibited since February 2025, in the €35 million or 7% of turnover penalty tier. Emotion recognition on customers wasn’t. The reasoning was roughly that a customer can hang up and go elsewhere while an employee can’t, so the customer-facing version sits in the high-risk category and stays permitted with obligations attached, and the employee-facing version is simply banned.
That distinction is clean in the legislation and messy in a contact centre, because voice analytics platforms don’t sit on one side of the call. They listen to both parties and produce outputs about both. The same software can be entirely legal pointed at the customer and prohibited pointed at the agent, and the vendor demo will usually show you the customer half.
The specific things to ask about are tone scoring applied to agents, stress or wellbeing flags, and any coaching feature that claims to measure empathy or emotional delivery.
It’s also worth knowing what isn’t caught, because there’s a lot of nervousness about speech analytics in general at the moment. Keyword spotting, silence detection, interruptions, call length, topic and intent classification are all unaffected. None of them infer emotion. The line sits at working out how a person feels from their voice.
Get the answer in writing.
Where does the AI disclosure appear?
If there’s a bot in front of your customers, they have to be told they’re talking to a machine, before or at the very start of the conversation.
The Commission’s guidance is unusually specific about what doesn’t satisfy this. A line in the terms and conditions won’t do it. Neither will a machine-readable watermark on its own. Calling the thing an “assistant” and leaving people to work it out doesn’t count either. It has to be visible inside the interaction.
Who is the provider and who is the deployer, for each system?
Different obligations attach to each role, and the roles aren’t always obvious from where you’re sitting. If your provider built or branded a bot, they’re probably the provider of it. If they’re running a third party tool on your behalf, it gets murkier. If you’ve put your own logo on something white-labelled, that might make you the provider of a system you didn’t build.
I’d want this written down system by system rather than discussed in general terms once a quarter.
Is your generative tooling marking its output?
Generative systems have to mark what they produce as AI-generated, in a machine-readable way. Anything already on the market before 2 August got until 2 December to sort it out. Anything newer had to comply from the start.
That’s one email to your provider and one from them to their vendor.
What AI literacy training do the agents actually have?
This is the one I’d have missed.
The literacy duty doesn’t stop at your own payroll. It extends to other people operating AI systems on your behalf, and the Commission has been explicit that contractors and service providers are included. So the agents handling your queue from another country sit inside your obligation, not only your provider’s.
What’s less clear, at least to me, is how much is enough. The wording asks you to support the development of AI literacy rather than guarantee any particular standard, and it’s meant to be calibrated to the people and the context. In practice I’d want to know that something exists, that it relates to the tools those agents actually touch, and that someone wrote it down. Whether that’s sufficient is not a question I think anyone can answer with confidence yet, and I’d be a bit wary of a provider who says otherwise.
When the bot gets it wrong, who pays?
Not a regulatory question, this one. But important to think about
Air Canada argued in front of a tribunal that its chatbot was a separate legal entity, responsible for its own statements. It lost. Whatever the automation promises, you promised.
So ask what happens when a bot invents a refund policy, and whether the answer appears anywhere in the contract.
You can read more on the act at https://artificialintelligenceact.eu/ or contact us here to talk over how this can affect you and your operations.
About the Author
I started turning spanners at sixteen and went on to lead global support for some of the world’s most demanding industries. I’ve built a reputation for challenging the traditional ways of doing things, and pushing the limits of what’s possible.
From transforming operations at Volvo to building human-centred support models at Sigma Technology and now FIXATE, I lead with clarity, care, and courage. I see the big picture, sweat the details, and always try to do what’s right, even when it’s hard.
If something’s worth doing, I want to do it properly. And I’m probably already thinking about how to make it better.
Read more from the author