EU AI Act deployer checklist for AI voice agents
Use this checklist when your organization operates an AI voice agent on a CPaaS platform and calls may involve people in the EU. It focuses on telephone and voice-agent deployments; it is not a general guide to the EU AI Act and is not legal advice. Ask qualified counsel to confirm how the Act applies to your use case and the GDPR roles and duties attached to your call data. For the industry-news overview of what changed and when, read EU AI Act 2026: what it means for communications platforms and AI voice agents. This page takes the buyer-side view: who owns the deployment decisions, what to check, and which tenant controls can support that work.1. Decide which role your organization has
The Act assigns roles by what an organization does, not by whether a contract calls it a customer, vendor, or platform. Use this decision path as a starting point, then confirm the result with counsel.- Does your organization put the AI voice agent into service or use it under its authority for a business purpose? If yes, your organization is generally the deployer (Article 3(4)). A tenant that configures an agent and uses it to handle its customer calls is ordinarily the deployer for that use. Article 26 sets out deployer obligations for high-risk AI systems; other duties, including Article 50 transparency, have their own scope and conditions.
- Does your organization develop the AI system, or have it developed, and place it on the market or put it into service under its own name or trademark? It may also be a provider (Article 3(3)). A communications platform can have provider duties for an AI system it offers under its own name while its customer is the deployer of a configured voice-agent deployment. Do not assume one role excludes the other.
- Does the deployment touch the EU scope? Check where the system is placed on the market or put into service, where the deployer is established, and whether the system’s output is used in the EU (Article 2). A call’s telephone channel alone does not settle territorial scope.
- Could the agent be high-risk under Article 6 and Annex III, or has your organization changed an existing system’s intended purpose or made a substantial modification? Stop and get a use-case-specific legal classification. The high-risk deployer duties are not interchangeable with Article 50 transparency, and this checklist does not cover a full high-risk compliance program.
2. Six controls to review for customer-facing AI calls
These six lines combine direct duties where they apply with practical procurement and operating controls. They are not six universal statutory duties imposed on every voice-agent deployer: several requirements below attach specifically to high-risk systems or to providers. Confirm the legal basis and scope for your deployment.3. Map each control to a tenant-owned platform surface
A dashboard surface helps you configure or review a control; it does not make the legal decision or activate a complete compliance posture for you. Check the effective setting and the records for your own workspace.
For GDPR, also assess the call’s personal-data purposes, lawful basis, controller/processor allocation, data minimization, access, security, and retention. Complete a data-protection impact assessment where the processing is likely to result in high risk. The GDPR posture guide covers those tenant decisions; AI disclosure does not replace them.
4. What Devotel Orbit provides and what your organization owns
The platform supplies controls and records; it does not make your organization compliant or take ownership of your regulatory decisions. Some of the controls above are tenant choices, not automatic platform guarantees.
Procurement review before launch
- Confirm the system, intended use, EU connection, and your organization’s role with counsel.
- Ask the provider for the system instructions, technical information, known limitations, and evidence relevant to your deployment.
- Enable and test the spoken AI notice; keep it separate from recording consent and the GDPR privacy notice.
- Assign a staffed human route and test failure and escalation cases.
- Set agent-version approval, evaluation, call-evidence access, and retention processes before launch.
- Define monitoring, incident ownership, provider escalation, and any required notifications.
- Re-run the review when the agent’s purpose, model, prompt, voice, handoff, or data use changes.