EU AI Act and GDPR for AI agents: a build checklist
What the EU AI Act and GDPR mean for a custom AI agent or voice agent: who the provider is, what Article 50 requires, the 2026 dates, data transfers and the controls that go into the build.
Since August 2, 2026, a support chatbot or voice agent that talks to people in the EU has to tell them it is an AI, at the latest at the first interaction. Breaching that duty can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower).
Most of what the EU AI Act and GDPR ask of an agent is engineering work: a line in the greeting, a log, an approval step, a region setting. This guide maps each rule to the build, as the law stands on October 8, 2026. Apptycoons builds custom AI agents with engineers in Karachi, Pakistan, so the transfers section describes our own setup.
Does the EU AI Act apply to your AI agent?
Yes, if the agent is placed on the EU market or its output is used in the EU. Article 2(1) covers providers placing AI systems on the EU market wherever they are established, deployers located in the EU, and providers and deployers in third countries “where the output produced by the AI system is used in the Union”. A US or UK company whose agent answers EU customers is in scope.
The Commission’s AI Act Service Desk says the term AI agent “is not legally defined”, but agents fall under the definition of an AI system, so the same rules apply. It calls its view on agents preliminary.
Who is the provider when an agency builds the agent?
Usually the client. Article 3(3) makes the provider whoever develops an AI system, or “has an AI system … developed and places it on the market or puts the AI system into service under its own name or trademark”. A company that commissions a custom agent and runs it under its own brand fits that definition, and because it uses the agent in its own business, it is normally the deployer as well (Article 3(4)).
That is our reading of the definitions, not a ruling, and a vendor selling one agent to many customers under its own brand is a provider itself. Write the split into the contract: who holds the Article 50 duties, who keeps the documentation, who answers a regulator.
GDPR draws a parallel line: you are normally the controller and the development partner the processor, which requires an Article 28 contract (a data processing agreement, or DPA).
What changed in 2026: the Digital Omnibus dates
The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk deadlines and left the chatbot rules on schedule. It entered into force on July 27, 2026, so pages giving August 2, 2026 as the high-risk date are out of date.
| Date | What applies |
|---|---|
| Feb 2, 2025 | Banned practices (Article 5) and AI literacy (Article 4) |
| Aug 2, 2025 | Rules for general-purpose AI models, governance and penalties |
| Aug 2, 2026 | General application, including the Article 50 transparency duties |
| Dec 2, 2026 | New Article 5 bans (non-consensual intimate imagery, child sexual abuse material); marking deadline for generative systems on the market before Aug 2, 2026 |
| Dec 2, 2027 | High-risk rules for Annex III uses (hiring, credit, insurance pricing and others) |
| Aug 2, 2028 | High-risk rules for AI in regulated products (Annex I) |
The Omnibus also softened Article 4: providers and deployers must now “take measures to support the development of AI literacy”, not ensure a sufficient level of it.
What Article 50 requires of chatbots and voice agents
An agent that talks to people must be designed so that they “are informed that they are interacting with an AI system, unless this is obvious” (Article 50(1)). The information has to arrive “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”, and it must meet accessibility requirements (Article 50(5)). The Commission’s FAQ names “chatbots, AI agents, and avatars”; a voice agent on a phone line is the same two-way exchange.
Three details are often misreported:
- Naming the company. Article 50(1) does not require the agent to say which business it works for. It is good practice, and the GDPR notice usually needs it anyway.
- The “obvious” exception. Don’t build on it. A voice agent designed to sound human is the opposite of obvious.
- Marking output. Article 50(2) is a separate duty: providers of systems that generate synthetic audio, image, video or text must mark the output “in a machine-readable format and detectable as artificially generated or manipulated”. A synthetic voice is synthetic audio. The grace period to December 2, 2026 covers only systems on the market before August 2, 2026.
Our AI voice agent development page covers how we build and test the greeting, transfer and recording flow.
Disclosure scripts for chat, voice and handoff
These are examples to adapt, not legal wording. The voice greeting combines the Article 50 disclosure with the GDPR Article 13 recording notice, because both have to come first.
- Chat, first message: “Hi, I’m [Company]’s AI assistant. I can check orders and book appointments. Type ‘person’ at any time to reach our team.”
- Inbound voice, greeting: “Thanks for calling [Company]. I’m an AI assistant. This call is recorded so we can handle your request, and we keep recordings for [30] days. You can find our privacy notice at [company.com/privacy] or ask for it by email. How can I help?”
- Before a transfer: “I’m transferring you to a member of our team. They’ll see a summary of our conversation.”
- Before a sensitive step: “As a reminder, you’re speaking with an AI assistant. Before I change your booking, I’ll read the details back for you to confirm.”
Keep the spoken notice short and put the full privacy notice online.
When does an AI agent become high-risk?
An agent becomes high-risk when it is used for an Annex III purpose. The ones closest to agent work: recruitment and selection of candidates (4(a)), decisions on terms of work, promotion or termination and the monitoring of workers (4(b)), creditworthiness and credit scoring, with fraud detection excluded (5(b)), risk assessment and pricing in life and health insurance (5(c)), and evaluating or classifying emergency calls (5(d)).
From December 2, 2027, those systems carry the Chapter III obligations: risk management, data governance, technical documentation, record-keeping, human oversight, and accuracy and cybersecurity.
A general customer-service, booking or FAQ agent is typically not high-risk. Add a step that screens job applicants or sets credit limits and it is. Draw that line in scope.
Banned practices to design out now
Article 5(1)(a) and (b) have applied since February 2, 2025. They ban manipulative or deceptive techniques that materially distort behavior and cause significant harm, and exploiting vulnerabilities linked to age, disability or social or economic situation.
For a sales or collections agent, design out the patterns that lean toward that line: invented deadlines, pressure on callers who sound confused, scripts that push harder when someone hesitates.
GDPR for agents: what still applies
GDPR applies to an agent the way it applies to any system that processes personal data, and it has not changed. The separate Digital Omnibus proposal to amend it (COM(2025) 837) was still in Parliament and Council when we checked on October 8, 2026.
The parts that turn into code:
- Lawful basis (Article 6). Pick it per purpose before the build.
- Minimization. Send the model only the fields the task needs.
- Retention. Transcripts, recordings, logs and vector-store chunks each need a deletion timer.
- DPIA (Article 35). Required before processing “likely to result in a high risk”, such as health data at scale.
- Automated decisions (Article 22). People have the right not to be subject to solely automated decisions with legal or similarly significant effects.
- Rights requests. Access and deletion must reach transcripts, logs and embeddings, not only the CRM.
Sub-processors in an agent stack
A voice or chat agent can involve five or six vendors that see personal data, and each belongs in the DPA as a sub-processor. Article 28 requires the controller’s prior authorization to use them.
| Component | What it sees | What to settle |
|---|---|---|
| Model API | Prompts, retrieved context, outputs | DPA, region, training and retention settings |
| Telephony | Phone numbers, call audio, call records | DPA, where recordings are stored |
| Speech-to-text | Caller audio | DPA, retention of audio and transcripts |
| Text-to-speech | The agent’s replies, which may contain personal data | DPA, how generated audio is marked |
| Vector database | Chunks of your documents and records | DPA, region, deletion on request |
| Hosting and logging | Everything the agent logs | DPA, region, log retention |
Model providers differ. OpenAI has not trained on API data by default since March 1, 2023, keeps abuse-monitoring logs for up to 30 days, offers zero data retention only with prior approval, and can keep both storage and processing in Europe (EEA and Switzerland); its UK region stores data there but may process it elsewhere. Anthropic’s own API currently offers inference in the US or globally and stores workspace data in the US, so EU residency for Claude means going through a cloud platform such as Google Cloud, where the endpoint sets the region. Check current terms before you write the privacy notice.
Working with engineers outside the EU: a transfer setup that holds up
Engineers outside the EU can work on a GDPR-covered system, but personal data sent to a country without an EU adequacy decision needs a transfer tool and an assessment. Pakistan, where our engineers work, is not on the Commission’s adequacy list. The setup we propose:
- Production data stays in your environment, in your cloud account and, when you require it, an EU region.
- Development and testing run on synthetic or redacted data.
- Production access is limited to named engineers, for a stated reason, and logged.
- Where personal data does reach Karachi, the EU standard contractual clauses apply: Module 2 (controller to processor) or Module 3 (processor to sub-processor), depending on who signs. They already contain the Article 28 terms, so no separate DPA is needed for that transfer.
- Clause 14 requires a transfer impact assessment of the destination country’s laws and practices, with extra safeguards such as encryption where needed. We supply the technical facts; your counsel signs off.
None of this means data “never leaves the EU”. Access from Karachi is a transfer and is documented as one.
UK buyers: what differs
The EU AI Act is not UK law, but it reaches a UK company whose agent’s output is used in the EU (Article 2(1)(c)). Personal data falls under UK GDPR, and EU-to-UK flows rely on the adequacy decisions the Commission renewed in December 2025.
Transfers out of the UK work differently. The ICO is explicit that “the EU SCCs are not valid on their own” for UK transfers: you use the ICO’s International Data Transfer Agreement (IDTA), or the UK Addendum attached to the EU SCCs, and you must complete a transfer risk assessment (TRA). The Data (Use and Access) Act 2025 also rewrote the UK rules on automated decision-making; check them before an agent decides anything significant on its own.
The build checklist
This is the list we work through in discovery and build for an agent with EU or UK users: a legal hook, a change in the system and a record you keep.
| Control | Legal hook | What goes into the build | Evidence you keep |
|---|---|---|---|
| Role mapping | AI Act Art. 3(3)–(4); GDPR Art. 28 | Provider, deployer, controller and processor agreed in discovery | Contract clause and role note |
| AI disclosure in chat | AI Act Art. 50(1), 50(5) | First message says it is an AI; readable by screen readers | Test case on the first turn |
| AI disclosure in voice | AI Act Art. 50(1); GDPR Art. 13 | Greeting with AI and recording notice before any question | Script version and test recording |
| Synthetic audio marking | AI Act Art. 50(2) | Marking agreed with the speech vendor | Vendor confirmation |
| Human handoff | GDPR Art. 22(3), where Art. 22 applies | Transfer on request and on low confidence | Handoff log |
| Approval steps | GDPR Art. 22; AI Act Art. 14 if high-risk | Human approval before actions that move money or change rights | Approval records |
| Action audit log | GDPR Art. 5(2), 32; AI Act Art. 12 if high-risk | Every tool call logged with input, output and actor | Log with a set retention |
| Minimization | GDPR Art. 5(1)(c) | PII redacted before the model call | Redaction tests |
| Retention timers | GDPR Art. 5(1)(e), 13(2)(a) | Auto-delete for transcripts, recordings, logs and chunks | Retention configuration |
| Region pinning | GDPR Chapter V | Model, storage and vector database in the chosen region | Deployment configuration |
| Model data settings | GDPR Art. 28; provider terms | No-training endpoints; zero retention where the provider offers and approves it | Provider settings and agreement |
| Sub-processor register | GDPR Art. 28(2) and (4) | Every service that touches personal data listed | DPA annex |
| Transfer tools | GDPR Art. 46; SCC Clause 14; UK IDTA or Addendum | SCCs and assessment for access from Karachi | Signed clauses and assessment |
| DPIA input | GDPR Art. 35 | System description and data-flow diagram for your DPIA | DPIA annex |
| Evaluation set and kill switch | GDPR Art. 32; AI Act Art. 15 if high-risk | Test set scored on every change; one switch to disable the agent or a tool | Evaluation reports |
When you don’t need to worry
Most agent projects carry less regulatory work than the headlines suggest. The effort stays small when:
- Nobody in the EU uses the agent and its output isn’t used there. The AI Act does not reach it (Article 2), and EU GDPR usually doesn’t either.
- The agent is a support, booking or FAQ agent. It is typically not high-risk. The work is disclosure, logging and a DPA, not a conformity assessment.
- The agent processes no personal data. An agent that reconciles supplier invoice totals raises few GDPR questions.
The cases that need care are Annex III uses, agents that decide things about people, and health data or call recordings at scale.
What to ask your development partner
Five questions show whether a partner has thought about this:
- Who is the provider and who is the deployer, and where does the contract say so?
- Where does each component run, and which can be pinned to an EU region?
- Which sub-processors see our data, and with what retention and training settings?
- Will you sign our DPA, plus the SCCs or the UK IDTA or Addendum, and support our transfer assessment?
- How is the AI disclosure built and tested, and how do we switch the agent off?
Our answers: we can sign your DPA and the SCCs or UK transfer documents, deploy in an EU region on request, use endpoints that exclude training (zero retention where the provider offers it), and supply the system description and sub-processor list for your DPIA. For wider vendor questions, use our checklist for evaluating an AI agent development company. To map your own agent against the table above, book a free AI audit.
This guide summarizes the law as of October 8, 2026 and is not legal advice. Check your situation with counsel or your data protection officer.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- Article 50: Transparency obligations for providers and deployers of certain AI systems, AI Act Service Desk, European Commission
- How are AI agents addressed within the AI Act?, AI Act Service Desk, European Commission
- Transparency obligations under Article 50 of the AI Act, European Commission
- New Standard Contractual Clauses - Questions and Answers overview, European Commission
- What are standard data protection clauses (the UK IDTA and the Addendum)?, ICO
AI Agent Development
We design and build autonomous AI agents and multi-agent systems that read, decide and act across your tools, with human approval where it matters.



