The EU AI Act compliance checklist for customer service teams
A practical, step-by-step checklist to help CX and customer service leaders comply with the EU AI Act obligations that apply from August 2, 2026
Add bookmark
From August 2, 2026, any organization using artificial intelligence (AI) in customer service for EU customers must disclose AI use at the point of interaction, offer a route to a human, disclose emotion recognition systems, and evidence staff AI literacy. Despite the EU's "Digital Omnibus" agreement delaying some high-risk obligations to December 2027, these customer-facing transparency requirements were not postponed and remain in force from August.
This checklist breaks down what customer service and CX teams need to have in place, and by when. For the strategic picture of the key actions to take before the Act comes into force, see our companion piece here.
Don't miss any news, updates or insider tips from CX Network by getting them delivered to your inbox. Sign up to our newsletter and join our community of experts.
What still applies from August 2, 2026 - and what was delayed?
The EU AI Act became legally binding in 2024 and its obligations have been phased in since. In May 2026, EU lawmakers reached political agreement on the Digital Omnibus, deferring obligations for high-risk AI systems to December 2027 and sector-specific requirements to August 2028.
Crucially for CX teams, the Article 50 transparency obligations – covering chatbots, AI-generated content, and emotion recognition disclosure – were not part of the deferral. National market surveillance authorities can enforce them from August 2, 2026.
CX practitioners are already responding: when CX Network conducted its annual research into the state of CX, 32 percent of respondents said they expect spending on AI regulatory compliance to increase this year.

EU AI Act compliance checklist for customer service
1. Audit and classify every AI system that touches customers
Inventory every AI touchpoint in the customer journey: service chatbots, voice bots, routing algorithms, sentiment analysis, agent-assist tools, and AI-driven recommendations. Classify each against the Act's risk tiers – most service bots fall under transparency-only obligations, but systems influencing access to essential services, credit, or insurance may be high risk.
Sue Duris, principal consultant at M4 Communications, urges practitioners to treat this groundwork as non-negotiable: "Get the foundations right before you deploy, or your AI investment becomes a trust liability."

2. Build AI disclosure into the interaction itself
By August 2, 2026, customers must be informed they are interacting with AI at the first point of contact, unless it is already obvious. Generic declarations buried in policy pages will not suffice; disclosure must appear in the moment, in plain language.
This is not just a compliance exercise. CX Network's research found that awareness of how AI works and uses customer data is now the number-one customer behavior shaping CX planning, selected by 36 percent of practitioners.
3. Give customers a route to a human – and plan for it operationally
Customers who do not want to interact with AI must be able to continue their query another way. That has workforce management consequences: deflection-based ROI models and staffing plans need contingency for opt-out volumes, separate routing rules, and human-only queues. Track your opt-out rate as a governance metric, not just a capacity variablea – rising rate is an early warning signal for AI trust issues.
4. Disclose emotion recognition and sentiment systems
If you deploy emotion recognition or biometric categorization systems in service interactions, you must inform customers from August 2026 and process the data in line with GDPR. These tools sit in the high-risk category, so while disclosure applies now, full high-risk compliance – including registration, conformity assessment, and continuous human oversight – is due by December 2027.
5. Evidence AI literacy across the service team
Article 4 obligations have applied since February 2025: providers and deployers must ensure a sufficient level of AI literacy among staff operating AI systems. For service teams, that means role-specific, scenario-based training, with documentation to prove it. Frontline agents, workforce planners, and vendor managers each need different competencies, from spotting erroneous AI outputs to understanding escalation judgment.
6. Close the governance gap
Organization-wide AI governance is improving but far from universal. CX Network's 2026 research found 43 percent of practitioners now have an organization-wide approach to AI governance, up from 37 percent in 2025 – but 20 percent still have none, and 12 percent govern AI at department level only.
Joshua Curtis, customer care center manager at Super Retail Group and a CX Network Advisory Board member, says AI has pulled compliance questions directly into the service function: "Today, privacy decisions are being made inside customer experience platforms, workflows, and journeys often without a human involved. That brings the issue much closer to the front line."
Experienced oversight is what keeps those automated decisions compliant. Montserrat Padierna, customer knowledge and experience lead at Walmart Canada and a CX Network Advisory Board member, says: "Leaders with tenure and cross-functional understanding ensure prompts are refined, outputs are interpreted correctly and guardrails remain intact."
The minimum documentation required includes an AI system register, human oversight procedures, disclosure records, training logs, and an escalation policy.
7. Clarify provider vs. deployer responsibilities with vendors
Most CX teams are deployers of third-party AI rather than providers – 68 percent of practitioners acquire new AI capabilities through vendors, per CX Network's research. Your obligations differ accordingly, but they do not disappear. Review contracts for those who own conformity documentation, model updates, logging, and incident response, and ask vendors to demonstrate their own AI Act readiness before renewal.
Frequently asked questions
- Does the EU AI Act apply to my customer service chatbot? Yes, if it serves customers in the EU – regardless of where your organization is based. Standard support chatbots face transparency obligations from August 2, 2026; only bots involved in areas like credit decisions or biometrics trigger the high-risk regime.
- Which EU AI Act deadlines were delayed by the Digital Omnibus? High-risk system obligations moved to December 2027, and sector-specific requirements to August 2028. Chatbot transparency and emotion recognition disclosure obligations were not delayed and apply from August 2, 2026.
- What are the penalties for non-compliance? The most serious violations carry fines of up to €35 million or seven percent of global annual turnover, whichever is higher. Non-compliance with high-risk obligations carries fines of up to €15 million or three percent of turnover.
- Does the Act apply to companies outside the EU? Yes. Like GDPR, the AI Act has extraterritorial reach: it applies to any organization placing AI systems on the EU market or serving EU customers with them.
Quick links
- Top 30 contact center leaders to follow in 2026
- Why CX budgets are won at mid-year, not year-end
- Building context-aware customer service that works