3-day trial for €1, card required - view pricing

EU AI Act 2026: Why Every Voice and Chat AI Provider Is Now Open to a Cease-and-Desist Letter

EchoCall Team avatar

EchoCall Team

blog-details-cover

On August 2, 2026, Article 50 of the EU AI Act became applicable - with no grace period. Every company running a voice AI agent on the phone or a chatbot on its website must now tell callers and chatters, clearly and unambiguously, that they are talking to AI. Companies that skip this aren't heading toward a future violation - they are, as of this week, in breach of binding EU law. And according to several German law firms, the sharpest near-term risk isn't a regulatory fine at all - it's a competitor or trade association sending a cease-and-desist letter, no regulator involved.

The problem: most voice and chat AI providers haven't implemented this yet. We went through the EU AI Act's rules for voice and chat AI systems in detail, verified against primary sources (EUR-Lex, the European Commission, Germany's Bundesnetzagentur), and cross-checked against German unfair-competition law. Here's what actually applies - and what to fix this week.

The EU AI Act in 60 seconds

Regulation (EU) 2024/1689 (the "AI Act") entered into force on August 1, 2024, but becomes applicable in stages. The key dates:

DateWhat applies from this date
Aug 1, 2024Regulation enters into force (no operative obligations yet)
Feb 2, 2025Prohibited practices (Art. 5) and AI literacy obligation (Art. 4)
Aug 2, 2025Obligations for General-Purpose AI (GPAI) models, governance and penalty provisions
Aug 2, 2026Transparency obligations (Art. 50) and high-risk obligations for Annex III systems - no grace period
Dec 2, 2026End of the transition period for technically marking synthetic content (Art. 50(2)) for pre-existing systems
Aug 2, 2027Post-market monitoring (Art. 6(1)), final deadlines for legacy GPAI models, Annex I product-safety high-risk systems begin
Aug 2, 2030High-risk AI systems used by public authorities must be fully compliant

In other words, we're in the middle of the single most significant rollout wave of the entire regulation: transparency obligations and a large share of the high-risk rules took effect yesterday relative to this article.

The core obligation: Art. 50(1) - the AI disclosure duty

The core obligation is unambiguous: providers of AI systems intended for direct interaction with natural persons must ensure those persons are informed, at the latest at the time of the first interaction, clearly and understandably, that they are interacting with an AI system.

This explicitly applies to automated phone systems - the European Commission names "automated phone systems" directly as an example in its official FAQ on Art. 50. The same duty applies to chatbots.

There is one exception: if it is obvious to a "reasonably well-informed, observant and circumspect" person that they are interacting with AI, the explicit disclosure duty falls away. In practice, this exception rarely holds up for an actual phone call - a call that sounds like a human conversation is, by definition, not "obvious" AI. Relying on this exception is a high-risk bet.

The other three parts of Art. 50

Article 50 covers four distinct scenarios that are often conflated:

  • Para. 1 - the AI disclosure duty toward end users (above) - this is the obligation that applies as of yesterday, with zero grace period.
  • Para. 2 - machine-readable marking of AI-generated content (text, image, audio, video) by the provider. There's a transition period until December 2, 2026 for systems already on the market before Aug 2, 2026, and a Code of Practice standard the European Commission confirmed as adequate in July 2026 that companies can rely on.
  • Para. 3 - deployers of emotion-recognition or biometric-categorization systems must inform the people exposed to them.
  • Para. 4 - labeling duty for deepfakes: AI-generated audio, image, or video content that makes a real person, event, or place falsely appear genuine.

For a standard customer-service setup (a voice agent on the phone, a chatbot on the website), paragraph 1 is the obligation that applies right now. Paragraph 2 mainly concerns technical marking of generated audio files and still has time until December. Paragraph 4 becomes relevant only once a real person's voice is being cloned.

The underrated risk: not the regulator, the cease-and-desist letter

Most AI Act discussions center on fines from supervisory authorities. That's important, but it understates the actually acute risk in Germany: the competitor cease-and-desist letter ("Abmahnung").

Several German law firms (including tww.law, Kanzlei Heidicker, and Prigge Recht) independently arrive at the same conclusion: Art. 50 AI Act likely qualifies as a market-conduct rule under § 3a of Germany's Unfair Competition Act (UWG) - directly analogous to how German courts have already treated GDPR violations. In practice, that means:

  • Not just authorities, but competitors and qualified trade or consumer associations can send cease-and-desist letters.
  • No administrative proceeding is required first - a letter can arrive within days.
  • Germany's Wettbewerbszentrale already published preparatory guidance on labeling obligations in February 2026 - a clear signal that enforcement is being prepared.
  • Law firms explicitly draw a parallel to the influencer-disclosure cease-and-desist wave of recent years - a mass phenomenon that caught many companies off guard.

For companies running voice AI or chatbots, this means a single competitor can send a cease-and-desist letter simply because your voice agent doesn't identify itself as AI - regardless of whether any regulator ever gets involved.

Who's liable? Provider vs. deployer - and the white-label trap

The AI Act draws a strict line between two roles:

  • Provider: whoever develops an AI system, or has one developed, and places it on the market under its own name or trademark.
  • Deployer: whoever uses an AI system under its own authority.

A SaaS company offering a voice/chat AI platform is typically the provider of the base system. The customer configuring that platform for its own business is typically the deployer.

Two details are commonly overlooked:

  1. Art. 25(1)(a) - the white-label trap: putting your own brand on an AI system already placed on the market can make you a provider yourself - highly relevant for reseller and white-label models, where a given deployment turns out to be high-risk.
  2. Art. 25(1)(c) - the purpose-change trap: configuring a generic AI platform to serve a high-risk purpose (see next section) makes you the provider of that newly created system - with the full statutory obligations that come with it.

The high-risk trap: when does your chatbot become a "high-risk AI system"?

Annex III of the AI Act lists categories that are automatically classified as high-risk - particularly relevant for voice/chat systems:

  • Access to essential public services and government benefits
  • Creditworthiness assessment and credit scoring of natural persons
  • Risk assessment and pricing for life and health insurance

A voice AI agent used by an insurer or a bank isn't automatically high-risk - there's an important exception (Art. 6(3), the "escape valve"): systems that perform only a narrow, preparatory, or procedural task and don't replace the actual decision aren't classified as high-risk. But that exception disappears the moment a system performs profiling of natural persons - at that point, it is always high-risk.

In practice: an agent that just gathers information and hands it to a human for a decision is generally uncritical. An agent that algorithmically pre-decides creditworthiness or insurance risk becomes high-risk - triggering obligations such as a risk-management system, data governance, technical documentation, logging, human oversight, and EU registration.

Prohibited practices (Art. 5) - what's never allowed

In force since February 2025, but still relevant to how any AI system is configured:

  • Subliminal or manipulative techniques that materially distort a person's ability to make decisions and cause significant harm
  • Deliberately exploiting vulnerabilities (age, disability, economic hardship)
  • Social scoring - evaluating people by social behavior with unrelated, detrimental consequences
  • Emotion recognition in the workplace or educational settings (an outright ban, with narrow exceptions)
  • Biometric categorization used to infer sensitive traits like ethnicity, political opinion, or sexual orientation

For outbound voice AI campaigns, this means: scripts deliberately targeted at vulnerable groups (say, aggressive financial-product pitches aimed at the elderly) sit not just in a legal gray area, but in a prohibited one.

Fines at a glance

ViolationFine range
Prohibited practices (Art. 5)up to €35M or 7% of global annual turnover
Other obligations, incl. Art. 50 (transparency)up to €15M or 3% of global annual turnover
Providing incorrect information to authoritiesup to €7.5M or 1% of global annual turnover

Small and medium-sized businesses benefit from a reduction (50% for SMEs, 75% for micro-enterprises). In Germany, the Bundesnetzagentur is the central market-surveillance and complaints authority for the AI Act, following the implementing law (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG) passed by the Bundestag in summer 2026.

The 7-point checklist: what to do now

  1. Enforce the AI disclosure technically, not just on paper - an announcement or message at the start of every call or chat that no individual employee can forget or turn off.
  2. Put your intended purpose in writing: state clearly that your AI systems are not intended for automated final decisions on credit, insurance, or government-benefit matters without human oversight - this protects you from becoming a high-risk provider by accident.
  3. Check whether customers in high-risk industries (finance, insurance, government, healthcare) are actually running Annex III use cases, and document that assessment.
  4. Update your Terms and Privacy Policy: clarify provider/deployer roles, your intended purpose, and the technical AI disclosure.
  5. Don't leave recording consent to chance - if calls are recorded, consent needs to be obtained just as automatically as the AI disclosure.
  6. Review white-label/reseller agreements: put in writing who carries which information obligations when a reseller rebrands the product (Art. 25(4)).
  7. Run a prohibited-practices check on outbound scripts: no targeting of vulnerable groups, no emotional manipulation.

How EchoCall actually implemented this

We didn't just write this checklist - we shipped it the same day Art. 50 became applicable. Every EchoCall voice and chat agent now opens the conversation with an automatic AI disclosure - hard-wired into the system, not something a customer can turn off, automatically delivered in whichever language the conversation is happening in. When call recording is enabled, that's disclosed in the same announcement. Our Terms of Service and Privacy Policy were updated accordingly with AI Act role clarification and an explicit intended-purpose statement that rules out unsupervised high-risk decision-making. You'll find the rest of our compliance approach - including Zero-PII mode, ISO 27001 data centers, and GDPR compliance - on our security page and GDPR page.

FAQ: the EU AI Act for voice and chat AI systems

Do small businesses have to comply with the AI Act too?

Yes. The AI Act doesn't make obligations depend on company size - only the size of potential fines is reduced for SMEs (50%) and micro-enterprises (75%). A small business running a voice AI agent or chatbot must meet the Art. 50(1) disclosure duty exactly like a large enterprise.

Is mentioning the AI disclosure in the Terms of Service enough?

No. Art. 50(1) requires informing the specific person you're interacting with, at the latest when the interaction begins - so inside the call or chat window itself, not buried in a legal document almost nobody reads before calling.

What if my AI vendor doesn't build the disclosure in automatically?

Then the responsibility falls on you as the deployer to ensure it happens - and you carry the full cease-and-desist and fine exposure, even though the underlying technology comes from a third-party vendor. When choosing an AI provider, it's worth asking directly whether the disclosure is technically enforced or merely documented.

Does the AI Act apply to us if our company isn't based in the EU?

Yes, if your AI systems are used to interact with people in the EU. The AI Act's territorial scope follows where the effect occurs, not where the provider is headquartered.

Is a short announcement like "you're speaking with an AI" enough?

For Art. 50(1) in a standard customer-service context, yes - as long as the information is clear, understandable, and delivered at the start of the interaction. Emotion recognition, biometric categorization, or high-risk use cases add further, more specific disclosure obligations.

Does the labeling duty also apply to voice samples on a website?

In principle, yes - publicly available synthetic audio content falls under the AI-generated content labeling duty (Art. 50(2)), though with a transition period until December 2026 for pre-existing content. Anyone already publishing voice samples should label them as AI-generated now.


This article is not legal advice. It was compiled from publicly available primary sources (Regulation (EU) 2024/1689, European Commission guidance, Germany's Bundesnetzagentur) and assessments from German specialist law firms, and reflects the state as of August 3, 2026. For a legally binding assessment of your specific use case, consult a specialized law firm.

You might also like

Share this post
cta image
cta image

Ready to try EchoCall?

Start a 3-day trial for €1 at hub.echocall.de - card required, automatically refunded.