Answers · one question, one page

Is it legal to use an AI agent with customers in the EU?

Updated 2026-09-04 · 538 words · answered from our own prices and projects

Short answerread in a minute

Yes, with conditions. The customer must be told they are talking to an assistant; personal data must be handled under GDPR, with a data processing agreement with the model provider and a privacy notice that says an assistant is used; and the transparency rules of the EU AI Act apply to systems that interact with people.

This is a plain summary prepared for your lawyer to confirm, not legal advice. Our own rules go further than the minimum and are on the trust page.

Read our rules on drafts, data and disclosure →

The duty to disclose

A person interacting with an AI system must be told so, unless it is obvious from the context. For a chat or an email assistant that is not obvious, so the assistant says it is one, at the start and when it hands over. This is the transparency rule of the EU AI Act for systems that interact with people, and it is also simply what customers expect.

We build the disclosure into every agent as text the customer sees, not as a line in the terms.

Recording and data

A customer’s messages are personal data. Under GDPR the business needs a lawful basis for processing them, a privacy notice that says an assistant is used and what it does, and a data processing agreement with the provider whose model reads the messages. Data should be kept only as long as needed and the customer can ask what is held.

Voice adds a step: recording a call requires telling the caller, and in several countries their consent; the rule differs by country. Health data and payment data are special categories with stricter rules. We do not put an agent on those without the agreement and the notice in place first.

  • A lawful basis and a privacy notice that mentions the assistant
  • A data processing agreement with the model provider
  • Retention limits and a way to answer access requests
  • Extra rules for voice, health and payment data

What the AI Act asks of a small business

For a customer-facing assistant that answers questions and drafts replies, the AI Act mainly asks for transparency: tell people they are dealing with AI, and label AI-generated content where required. Assistants used for decisions about people, for example credit, hiring or access to services, fall under stricter high-risk rules, and we do not build those.

The transparency obligations apply from August 2026. A small business using an assistant for enquiries, bookings and repeating questions is in the light end of the law; the work is in the notice, the agreement and the rules, not in registration.

What we put in place by default

Disclosure text the customer sees; a person approving anything sent until you decide otherwise; no answers about money or health from the agent; logs you can read; a data processing agreement with the provider in your name; and a paragraph for your privacy notice, prepared for your lawyer to confirm. These are the same rules we run on our own assistant.

When this answer does not work

When this summary is not enough

If the agent talks on the phone, works with patients, handles payments or makes any decision about a person, the rules are stricter and country-specific, and this page does not cover them. If your customers are outside the EU, other laws apply. In every case: this is a summary prepared for your lawyer to confirm, written by an agency, not by a law firm.

Questions

Related questions

Do we have to tell customers they are talking to an AI agent?

Yes. The EU AI Act requires transparency for systems that interact with people, and customers expect it. Every agent we build says it is an assistant at the start and at the handover.

Do we need a contract with the AI provider for GDPR?

Yes, a data processing agreement, because the provider’s model reads personal data on your behalf. We set it up in your name as part of the build.

Is an AI agent for enquiries considered high-risk under the AI Act?

No, as far as we understand the law: answering questions and drafting replies is not a decision about a person. Systems that decide on credit, hiring or access to services are high-risk, and we do not build those. Confirm with your lawyer.

Send this page to your lawyer, then to us.

We build the disclosure, the agreement and the rules into the agent from the first day.