What the EU AI Act specifically requires from AI on the phone
The rule is in Article 50(1) of the AI Act, formally Regulation (EU) 2024/1689: providers must design and develop AI systems intended for direct interaction with natural persons so that the persons are informed that they're interacting with an AI system. The only exception is when that's obvious from the circumstances to a reasonably well-informed, observant, and circumspect person. A phone assistant that picks up with a natural voice is exactly that kind of system. A chatbot can write “AI chat” across its window; on the phone there's no window. The notice has to be in the conversation, and the simplest place for it is the first sentence.
The wording is more compact than many expect. It requires information, not consent: the caller doesn't have to agree, they have to know. It doesn't require registration in an EU database or a conformity procedure, since those are duties for high-risk systems (more on that below). And it's addressed to the provider of the system: whoever builds and places it on the market has to build in the introduction. The law firm Morgan Lewis sums it up in its overview from August 12, 2026 like this: which duties apply to an organization depends on whether it's the provider or the deployer of the system. For you as a business, that means in practice: your provider has to deliver it, you should verify it, because it's your business answering the phone, not the provider's. What an AI phone assistant even is and what it takes on is on the overview page.
Digital Omnibus: what was postponed, and what wasn't
On July 27, 2026, the Digital Omnibus to the AI Act took effect, Regulation (EU) 2026/1744. It mainly postpones the high-risk duties. It left the transparency duty from Article 50(1) untouched; the law firm Goodwin titled its analysis from August 3, 2026 “Not Delayed, Not Deferred” for exactly that reason. What this means for an AI phone assistant is in the table:
| Duty | Applies from | Relevant to AI phone assistants? |
|---|---|---|
| Information during direct interaction (Art. 50(1)) | August 2, 2026, unchanged | Yes. The assistant must identify itself as AI. |
| Labeling of AI-generated audio, image, video, and text content (Art. 50(2)) | August 2, 2026; for systems already on the market before, December 2, 2026 | A provider duty. Whether and how it covers spoken responses on the phone is for your provider to clarify, not you. |
| AI literacy of staff (Art. 4) | since February 2, 2025; softened by the Omnibus to measures that promote it | Yes, as a deployer: whoever handles the callback list and the summaries should know what the AI can and can't do. |
| High-risk duties for systems under Annex III | December 2, 2027 (previously August 2, 2026) | No. Answering calls and booking appointments aren't listed in Annex III. |
| High-risk duties for AI in regulated products (Annex I) | August 2, 2028 | No. |
On the high-risk question: Annex III of the regulation lists the areas where AI is treated as high-risk, including education, employment and staff selection, access to essential services, and law enforcement. Answering calls, capturing requests, and booking appointments isn't on that list. As things stand today, an AI phone assistant used for these tasks doesn't fall under the high-risk rules. That's an assessment, not a guarantee, and it depends on the use case: as soon as an AI on the phone evaluates job applicants or decides on access to benefits, Annex III is back in play. The law firm Gibson Dunn has compiled the new deadlines in its Omnibus overview.
GDPR and the AI Act: two frameworks, one call
Both laws meet in the same call but regulate different things. GDPR deals with the data: who processes what on whose behalf (a data processing agreement), how callers are informed about the processing (privacy policy), how long something is kept (deletion periods), where the servers are. The AI Act deals with deception: the caller should know that a machine is speaking. A business can comply with GDPR perfectly and still violate Article 50 if the assistant presents itself as “Ms. Miller from reception.” The reverse holds too.
What GDPR specifically requires is covered in the article Is an AI phone assistant GDPR-compliant? Whether and how a call may be recorded is a separate data protection and criminal law question that we deliberately don't cover here.
Checklist: how a business implements the transparency duty
- Listen to the introductory sentence. Call your own number and let the assistant answer. Does it say in the first sentence that it's an AI? If the notice only comes after the appointment question, or not at all, that's the first item to raise with your provider.
- Ask your provider how they implement Article 50. Who makes sure the introduction happens in every call, even after updates? Get that in writing.
- Follow up on GDPR paperwork: a data processing agreement, a privacy policy, a record of processing activities. That's GDPR, not the AI Act, but it belongs to the same call.
- Inform your team. Who gets the callback list, who gets the summaries, what do your people say when a customer asks “Was that just an AI?” Article 4 requires deployers to take measures that promote staff AI literacy; a short briefing is one such measure. You can put this in writing in an AI policy; our AI acceptable use policy template is free.
- Check the announcement text. If a recorded message still plays before the assistant, it shouldn't pretend a human is waiting either. Templates for that: answering machine greetings for businesses.
- Test call with fresh ears. Have someone who doesn't know the system call in, then ask afterward: "Did you know you were talking to an AI?" If the answer hesitates, the notice was too quiet.
What happens for violations?
The fines are set out in Article 99. For violations of the transparency duties in Article 50, paragraph 4 provides for fines of up to €15 million or, for companies, up to 3 percent of total worldwide annual turnover in the preceding financial year, whichever is higher. For SMEs, including start-ups, paragraph 6 applies the lower of the two amounts. Whether and how much a fine is imposed depends, under paragraph 7, on the circumstances of the individual case; member states may also, under paragraph 1, provide for warnings and non-monetary measures.
Responsible in Germany: since July 29, 2026, the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG, Germany's AI market surveillance and innovation promotion act) has been in force. It makes the Bundesnetzagentur (Federal Network Agency) the market surveillance authority, point of contact, and complaints office for the AI Act, while also building on the responsibilities of existing market surveillance authorities, per the Federal Ministry for Digital Affairs and State Modernization in its press release from July 29, 2026. A caller who feels deceived now has somewhere to turn.
What the AI Act requires, and what Steffi does
| What the AI Act requires | What Steffi does |
|---|---|
| Callers learn that an AI is speaking (Art. 50(1)) | Set up by default to introduce herself as AI first thing on the phone. |
| No pretending to be human (Recital 132: deception) | Never pretends to be a person. The voice sounds natural, and the AI notice belongs in the greeting. |
| High-risk procedures: not required for answering calls (Annex III) | Answers calls, captures requests, books appointments. She doesn't give legal, tax, or medical advice; she takes down the request and announces the callback. |
| Not required by the AI Act, standard for us anyway | Only answers what you've approved beforehand; before launch you listen to test calls. Processing under GDPR with a data processing agreement and clear deletion periods. |
What that sounds like in a real call is described on the page about Steffi; how to spot a properly set-up AI on the phone even without this notice is the checklist Detecting AI calls.
Sources and last checked
- Regulation (EU) 2024/1689 (the AI Act), EUR-Lex: Art. 4, Art. 50, Art. 99, Annex III.
- Regulation (EU) 2026/1744 (Digital Omnibus to the AI Act), EUR-Lex, in force since July 27, 2026.
- European Commission: Guidelines on the transparency obligations for providers and deployers of AI systems, adopted July 20, 2026.
- Goodwin: “Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Force”, August 3, 2026.
- Morgan Lewis: “EU AI Act's Transparency Rules: What Went Into Effect on 2 August?”, August 12, 2026.
- Gibson Dunn: “EU AI Act Omnibus Agreement”, May 27, 2026.
- BMDS: “Neues KI-Gesetz tritt in Kraft”, press release 47/2026, July 29, 2026.
This article is not legal advice. It reflects the status as of August 30, 2026; for your specific case, a data protection officer or a specialized lawyer can help. What an assistant costs for your business is clarified in the free intro call.