AI strategy · · 11 min

EU AI Act and GDPR for AI agents: a build checklist

What the EU AI Act and GDPR mean for a custom AI agent or voice agent: who the provider is, what Article 50 requires, the 2026 dates, data transfers and the controls that go into the build.

Since August 2, 2026, a support chatbot or voice agent that talks to people in the EU has to tell them it is an AI, at the latest at the first interaction. Breaching that duty can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower).

Most of what the EU AI Act and GDPR ask of an agent is engineering work: a line in the greeting, a log, an approval step, a region setting. This guide maps each rule to the build, as the law stands on October 8, 2026. Apptycoons builds custom AI agents with engineers in Karachi, Pakistan, so the transfers section describes our own setup.

Does the EU AI Act apply to your AI agent?

Yes, if the agent is placed on the EU market or its output is used in the EU. Article 2(1) covers providers placing AI systems on the EU market wherever they are established, deployers located in the EU, and providers and deployers in third countries “where the output produced by the AI system is used in the Union”. A US or UK company whose agent answers EU customers is in scope.

The Commission’s AI Act Service Desk says the term AI agent “is not legally defined”, but agents fall under the definition of an AI system, so the same rules apply. It calls its view on agents preliminary.

Who is the provider when an agency builds the agent?

Usually the client. Article 3(3) makes the provider whoever develops an AI system, or “has an AI system … developed and places it on the market or puts the AI system into service under its own name or trademark”. A company that commissions a custom agent and runs it under its own brand fits that definition, and because it uses the agent in its own business, it is normally the deployer as well (Article 3(4)).

That is our reading of the definitions, not a ruling, and a vendor selling one agent to many customers under its own brand is a provider itself. Write the split into the contract: who holds the Article 50 duties, who keeps the documentation, who answers a regulator.

GDPR draws a parallel line: you are normally the controller and the development partner the processor, which requires an Article 28 contract (a data processing agreement, or DPA).

What changed in 2026: the Digital Omnibus dates

The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk deadlines and left the chatbot rules on schedule. It entered into force on July 27, 2026, so pages giving August 2, 2026 as the high-risk date are out of date.

EU AI Act dates after Regulation (EU) 2026/1744
DateWhat applies
Feb 2, 2025Banned practices (Article 5) and AI literacy (Article 4)
Aug 2, 2025Rules for general-purpose AI models, governance and penalties
Aug 2, 2026General application, including the Article 50 transparency duties
Dec 2, 2026New Article 5 bans (non-consensual intimate imagery, child sexual abuse material); marking deadline for generative systems on the market before Aug 2, 2026
Dec 2, 2027High-risk rules for Annex III uses (hiring, credit, insurance pricing and others)
Aug 2, 2028High-risk rules for AI in regulated products (Annex I)

The Omnibus also softened Article 4: providers and deployers must now “take measures to support the development of AI literacy”, not ensure a sufficient level of it.

What Article 50 requires of chatbots and voice agents

An agent that talks to people must be designed so that they “are informed that they are interacting with an AI system, unless this is obvious” (Article 50(1)). The information has to arrive “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”, and it must meet accessibility requirements (Article 50(5)). The Commission’s FAQ names “chatbots, AI agents, and avatars”; a voice agent on a phone line is the same two-way exchange.

Three details are often misreported:

  • Naming the company. Article 50(1) does not require the agent to say which business it works for. It is good practice, and the GDPR notice usually needs it anyway.
  • The “obvious” exception. Don’t build on it. A voice agent designed to sound human is the opposite of obvious.
  • Marking output. Article 50(2) is a separate duty: providers of systems that generate synthetic audio, image, video or text must mark the output “in a machine-readable format and detectable as artificially generated or manipulated”. A synthetic voice is synthetic audio. The grace period to December 2, 2026 covers only systems on the market before August 2, 2026.

Our AI voice agent development page covers how we build and test the greeting, transfer and recording flow.

Disclosure scripts for chat, voice and handoff

These are examples to adapt, not legal wording. The voice greeting combines the Article 50 disclosure with the GDPR Article 13 recording notice, because both have to come first.

  • Chat, first message: “Hi, I’m [Company]’s AI assistant. I can check orders and book appointments. Type ‘person’ at any time to reach our team.”
  • Inbound voice, greeting: “Thanks for calling [Company]. I’m an AI assistant. This call is recorded so we can handle your request, and we keep recordings for [30] days. You can find our privacy notice at [company.com/privacy] or ask for it by email. How can I help?”
  • Before a transfer: “I’m transferring you to a member of our team. They’ll see a summary of our conversation.”
  • Before a sensitive step: “As a reminder, you’re speaking with an AI assistant. Before I change your booking, I’ll read the details back for you to confirm.”

Keep the spoken notice short and put the full privacy notice online.

When does an AI agent become high-risk?

An agent becomes high-risk when it is used for an Annex III purpose. The ones closest to agent work: recruitment and selection of candidates (4(a)), decisions on terms of work, promotion or termination and the monitoring of workers (4(b)), creditworthiness and credit scoring, with fraud detection excluded (5(b)), risk assessment and pricing in life and health insurance (5(c)), and evaluating or classifying emergency calls (5(d)).

From December 2, 2027, those systems carry the Chapter III obligations: risk management, data governance, technical documentation, record-keeping, human oversight, and accuracy and cybersecurity.

A general customer-service, booking or FAQ agent is typically not high-risk. Add a step that screens job applicants or sets credit limits and it is. Draw that line in scope.

Banned practices to design out now

Article 5(1)(a) and (b) have applied since February 2, 2025. They ban manipulative or deceptive techniques that materially distort behavior and cause significant harm, and exploiting vulnerabilities linked to age, disability or social or economic situation.

For a sales or collections agent, design out the patterns that lean toward that line: invented deadlines, pressure on callers who sound confused, scripts that push harder when someone hesitates.

GDPR for agents: what still applies

GDPR applies to an agent the way it applies to any system that processes personal data, and it has not changed. The separate Digital Omnibus proposal to amend it (COM(2025) 837) was still in Parliament and Council when we checked on October 8, 2026.

The parts that turn into code:

  • Lawful basis (Article 6). Pick it per purpose before the build.
  • Minimization. Send the model only the fields the task needs.
  • Retention. Transcripts, recordings, logs and vector-store chunks each need a deletion timer.
  • DPIA (Article 35). Required before processing “likely to result in a high risk”, such as health data at scale.
  • Automated decisions (Article 22). People have the right not to be subject to solely automated decisions with legal or similarly significant effects.
  • Rights requests. Access and deletion must reach transcripts, logs and embeddings, not only the CRM.

Sub-processors in an agent stack

A voice or chat agent can involve five or six vendors that see personal data, and each belongs in the DPA as a sub-processor. Article 28 requires the controller’s prior authorization to use them.

Who sees what in a typical agent stack
ComponentWhat it seesWhat to settle
Model APIPrompts, retrieved context, outputsDPA, region, training and retention settings
TelephonyPhone numbers, call audio, call recordsDPA, where recordings are stored
Speech-to-textCaller audioDPA, retention of audio and transcripts
Text-to-speechThe agent’s replies, which may contain personal dataDPA, how generated audio is marked
Vector databaseChunks of your documents and recordsDPA, region, deletion on request
Hosting and loggingEverything the agent logsDPA, region, log retention

Model providers differ. OpenAI has not trained on API data by default since March 1, 2023, keeps abuse-monitoring logs for up to 30 days, offers zero data retention only with prior approval, and can keep both storage and processing in Europe (EEA and Switzerland); its UK region stores data there but may process it elsewhere. Anthropic’s own API currently offers inference in the US or globally and stores workspace data in the US, so EU residency for Claude means going through a cloud platform such as Google Cloud, where the endpoint sets the region. Check current terms before you write the privacy notice.

Working with engineers outside the EU: a transfer setup that holds up

Engineers outside the EU can work on a GDPR-covered system, but personal data sent to a country without an EU adequacy decision needs a transfer tool and an assessment. Pakistan, where our engineers work, is not on the Commission’s adequacy list. The setup we propose:

  • Production data stays in your environment, in your cloud account and, when you require it, an EU region.
  • Development and testing run on synthetic or redacted data.
  • Production access is limited to named engineers, for a stated reason, and logged.
  • Where personal data does reach Karachi, the EU standard contractual clauses apply: Module 2 (controller to processor) or Module 3 (processor to sub-processor), depending on who signs. They already contain the Article 28 terms, so no separate DPA is needed for that transfer.
  • Clause 14 requires a transfer impact assessment of the destination country’s laws and practices, with extra safeguards such as encryption where needed. We supply the technical facts; your counsel signs off.

None of this means data “never leaves the EU”. Access from Karachi is a transfer and is documented as one.

UK buyers: what differs

The EU AI Act is not UK law, but it reaches a UK company whose agent’s output is used in the EU (Article 2(1)(c)). Personal data falls under UK GDPR, and EU-to-UK flows rely on the adequacy decisions the Commission renewed in December 2025.

Transfers out of the UK work differently. The ICO is explicit that “the EU SCCs are not valid on their own” for UK transfers: you use the ICO’s International Data Transfer Agreement (IDTA), or the UK Addendum attached to the EU SCCs, and you must complete a transfer risk assessment (TRA). The Data (Use and Access) Act 2025 also rewrote the UK rules on automated decision-making; check them before an agent decides anything significant on its own.

The build checklist

This is the list we work through in discovery and build for an agent with EU or UK users: a legal hook, a change in the system and a record you keep.

EU AI Act and GDPR controls in an agent build
ControlLegal hookWhat goes into the buildEvidence you keep
Role mappingAI Act Art. 3(3)–(4); GDPR Art. 28Provider, deployer, controller and processor agreed in discoveryContract clause and role note
AI disclosure in chatAI Act Art. 50(1), 50(5)First message says it is an AI; readable by screen readersTest case on the first turn
AI disclosure in voiceAI Act Art. 50(1); GDPR Art. 13Greeting with AI and recording notice before any questionScript version and test recording
Synthetic audio markingAI Act Art. 50(2)Marking agreed with the speech vendorVendor confirmation
Human handoffGDPR Art. 22(3), where Art. 22 appliesTransfer on request and on low confidenceHandoff log
Approval stepsGDPR Art. 22; AI Act Art. 14 if high-riskHuman approval before actions that move money or change rightsApproval records
Action audit logGDPR Art. 5(2), 32; AI Act Art. 12 if high-riskEvery tool call logged with input, output and actorLog with a set retention
MinimizationGDPR Art. 5(1)(c)PII redacted before the model callRedaction tests
Retention timersGDPR Art. 5(1)(e), 13(2)(a)Auto-delete for transcripts, recordings, logs and chunksRetention configuration
Region pinningGDPR Chapter VModel, storage and vector database in the chosen regionDeployment configuration
Model data settingsGDPR Art. 28; provider termsNo-training endpoints; zero retention where the provider offers and approves itProvider settings and agreement
Sub-processor registerGDPR Art. 28(2) and (4)Every service that touches personal data listedDPA annex
Transfer toolsGDPR Art. 46; SCC Clause 14; UK IDTA or AddendumSCCs and assessment for access from KarachiSigned clauses and assessment
DPIA inputGDPR Art. 35System description and data-flow diagram for your DPIADPIA annex
Evaluation set and kill switchGDPR Art. 32; AI Act Art. 15 if high-riskTest set scored on every change; one switch to disable the agent or a toolEvaluation reports

When you don’t need to worry

Most agent projects carry less regulatory work than the headlines suggest. The effort stays small when:

  • Nobody in the EU uses the agent and its output isn’t used there. The AI Act does not reach it (Article 2), and EU GDPR usually doesn’t either.
  • The agent is a support, booking or FAQ agent. It is typically not high-risk. The work is disclosure, logging and a DPA, not a conformity assessment.
  • The agent processes no personal data. An agent that reconciles supplier invoice totals raises few GDPR questions.

The cases that need care are Annex III uses, agents that decide things about people, and health data or call recordings at scale.

What to ask your development partner

Five questions show whether a partner has thought about this:

  1. Who is the provider and who is the deployer, and where does the contract say so?
  2. Where does each component run, and which can be pinned to an EU region?
  3. Which sub-processors see our data, and with what retention and training settings?
  4. Will you sign our DPA, plus the SCCs or the UK IDTA or Addendum, and support our transfer assessment?
  5. How is the AI disclosure built and tested, and how do we switch the agent off?

Our answers: we can sign your DPA and the SCCs or UK transfer documents, deploy in an EU region on request, use endpoints that exclude training (zero retention where the provider offers it), and supply the system description and sub-processor list for your DPIA. For wider vendor questions, use our checklist for evaluating an AI agent development company. To map your own agent against the table above, book a free AI audit.

This guide summarizes the law as of October 8, 2026 and is not legal advice. Check your situation with counsel or your data protection officer.

Related service

We design and build autonomous AI agents and multi-agent systems that read, decide and act across your tools, with human approval where it matters.

Want this applied to your business?
Free 45-min AI audit with a senior architect.
Book the audit
FAQ

Common questions.

Does the EU AI Act apply to a UK or US company with EU customers?

Yes, if it places the AI system on the EU market or the system's output is used in the EU (Article 2(1)(a) and (c)). Being established outside the EU does not take a company out of scope. The AI Act is not UK law, so an agent used only by UK customers falls under UK GDPR and other UK law instead.

Is a customer-service chatbot high-risk under the EU AI Act?

Typically not. A general support, booking or FAQ agent is not on the Annex III list, although it still has the Article 50 disclosure duty and must avoid the Article 5 banned practices. It becomes high-risk if it is used for an Annex III purpose, such as screening job applicants, scoring credit, pricing life or health insurance or triaging emergency calls.

Did the Digital Omnibus delay the chatbot disclosure rules?

No. The Article 50 transparency rules apply from August 2, 2026. Regulation (EU) 2026/1744 moved the high-risk dates to December 2, 2027 and August 2, 2028, and gave generative AI systems already on the market before August 2, 2026 until December 2, 2026 for machine-readable marking of their output.

What are the fines for not disclosing a chatbot?

Breaching Article 50 can lead to fines of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups the cap is whichever of the two is lower. Prohibited practices under Article 5 carry up to 35 million euros or 7%.

Do callers have to agree to an AI voice agent recording the call?

GDPR does not make consent the only option. The business needs a lawful basis under Article 6, which may be consent, contract or legitimate interests depending on the purpose, and national rules on call recording can add requirements. Whatever the basis, callers must be told at the start that the call is recorded and why, with the full privacy notice easy to reach, and in the EU that they are speaking to an AI.

Can engineers outside the EU work on a GDPR-covered system?

Yes, with safeguards. Personal data sent to a country without an EU adequacy decision, such as Pakistan, needs a transfer tool such as the EU standard contractual clauses plus an assessment of the destination country's laws under Clause 14. Developing against synthetic or redacted data keeps most engineering work out of scope of the transfer.