The EU AI Act and Your Customer Conversations
What Changes on 2 August, and How We Handle It
6 min read

Disclaimer: this blog explains how we are interpreting the law and acting upon it, and does not constitute legal advice. Do speak to your own legal team about your own obligations.
If you use AI to talk to your customers, whether by chat, email or voice, a new set of EU rules is about to become real. The good news is that, for most ecommerce and customer service teams, this is far less dramatic than the headlines suggest. It's mostly about being honest about your use of AI.
From 2 August 2026, the transparency obligations of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) come into force. The core idea behind this part of the Act is simple: if a person is interacting with an AI system, they should know it. No hidden robots pretending to be Dave from the returns team.
We're doing the work to make sure DigitalGenius meets these rules ahead of the deadline, and this post explains both the law and our position. So you can tick the box on your own supplier assessment and get back to running your business.
What is the EU AI Act?
The AI Act is the EU's attempt to regulate artificial intelligence by risk rather than by technology. Instead of one rulebook for everything, it sorts AI systems into tiers: a small number of prohibited practices, a set of high-risk uses that carry heavy obligations, a middle band of limited-risk systems that mainly owe transparency, and everything else, which is largely left alone.
Most customer service AI, including DigitalGenius, sits firmly in that limited-risk band. High-risk is reserved for things like biometric identification, critical infrastructure, credit scoring, recruitment decisions and law enforcement. These are areas where a bad AI call can genuinely upend someone's life. Answering customer service queries such as "where's my order?" does not qualify, which is reassuring for everyone involved.
The implications for getting this wrong can be quite severe. After 2 August, regulators can fine up to €15m or 3% of worldwide turnover for Article 50 breaches.
What actually changes on 2 August?
The headline obligation is Article 50, the transparency rules. There are two parts that matter for customer conversations.
The first, Article 50(1), says that when an AI system interacts with a person, that person must be told they're dealing with AI. In practice, that's a clear disclosure in your chat, email and voice channels rather than a hard technical lift. The key wording is that it should be “obvious from context”. So anything that closely mimics a human or is likely to fool people, such as natural language text or an AI voice, needs to be labelled.
The second, Article 50(2), applies if you use AI-generated voice or other synthetic media. That output has to be marked as artificially generated. If your AI phone agent speaks in a synthesised voice, the fact that it's synthetic needs to be detectable.
That really is the substance of it for CX. There is no requirement to redesign your product, file paperwork with a regulator, or appoint an EU representative.
A quick word on the "Digital Omnibus"
Because nothing in Brussels stays still for long, the Act was amended in June 2026 by a package nicknamed the "Digital Omnibus." For customer service AI, the practical effects are modest and, on balance, helpful:
The Article 50(1) AI-interaction disclosure stays due on 2 August 2026 — no change.
The Article 50(2) synthetic-audio marking gained a grace period to 2 December 2026 for systems already in market.
A new prohibition on some sensitive and illegal AI-generated imagery takes effect from 2 December 2026. This is aimed at generative-media misuse and has no bearing on customer service use cases.
The AI-literacy duty (making sure your staff actually understand the tools they operate) was softened slightly, but remains good practice regardless.
The net effect: the transparency deadline is still 2 August 2026.
Where does DigitalGenius stand?
Two roles under the Act apply to us, and one very much does not.
We are a limited-risk AI provider. Our platform talks to real people across chat, email and voice, so the Article 50(1) disclosure obligation applies to us, and because our voice channel produces synthetic audio, so does the 50(2) marking obligation. We've built for both. Our chat and voice disclosures are in place, our AI-generated voice output is already marked as AI-generated, and our email disclosure is rolling out ahead of the deadline. We're not relying on the grace period.
We are also a deployer of third-party AI models alongside our own proprietary models. We apply governance over how those models are used, aligned to our ISO/IEC 42001-based AI management practices. Importantly, we use these models; we don't build and sell them, so the obligations that fall on model makers sit with them, not us.
And the part that matters most for procurement teams: DigitalGenius is not a high-risk AI system. A typical deployment doesn't fall under the EU's harmonised product legislation, and we're not used for any of the high-risk purposes the Act lists.
What this means for you
If you deploy DigitalGenius, that deployment alone does not turn you into the operator of a high-risk AI system. You inherit a supplier that has scoped its obligations, met the ones that apply, and can evidence it.
There is a sensible caveat worth stating plainly: your own position depends on how you use AI across other areas of your business. For customer service and ecommerce operations, that's rarely the case, but do seek your own legal advice.
As a reminder: this is a general explainer, not legal advice. For your specific circumstances, talk to qualified counsel. Second, the timelines and even the text of the Act can move, as the Digital Omnibus just demonstrated, so it's worth keeping an eye on the space rather than filing it under "done forever."
How we can help
For DigitalGenius customers, the AI-interaction transparency piece is handled at the platform level across your channels, and our compliance position is available to your procurement, legal and security teams on request. If your diligence process needs the detail — our applicability analysis, sub-processor information, DPA, SOC 2 report and the rest — we can share it under your existing terms.




