> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# EU AI Act deployer checklist for AI voice agents

> Classify your role, review six controls for customer-facing AI calls, and separate Devotel Orbit's platform surfaces from tenant-owned responsibilities.

# EU AI Act deployer checklist for AI voice agents

Use this checklist when your organization operates an AI voice agent on a CPaaS platform and calls may involve people in the EU. It focuses on telephone and voice-agent deployments; it is not a general guide to the EU AI Act and is not legal advice. Ask qualified counsel to confirm how the Act applies to your use case and the GDPR roles and duties attached to your call data.

For the industry-news overview of what changed and when, read [EU AI Act 2026: what it means for communications platforms and AI voice agents](/blog/eu-ai-act-communications-platform-2026). This page takes the buyer-side view: who owns the deployment decisions, what to check, and which tenant controls can support that work.

## 1. Decide which role your organization has

The Act assigns roles by what an organization does, not by whether a contract calls it a customer, vendor, or platform. Use this decision path as a starting point, then confirm the result with counsel.

1. **Does your organization put the AI voice agent into service or use it under its authority for a business purpose?** If yes, your organization is generally the **deployer** (Article 3(4)). A tenant that configures an agent and uses it to handle its customer calls is ordinarily the deployer for that use. Article 26 sets out deployer obligations for high-risk AI systems; other duties, including Article 50 transparency, have their own scope and conditions.
2. **Does your organization develop the AI system, or have it developed, and place it on the market or put it into service under its own name or trademark?** It may also be a **provider** (Article 3(3)). A communications platform can have provider duties for an AI system it offers under its own name while its customer is the deployer of a configured voice-agent deployment. Do not assume one role excludes the other.
3. **Does the deployment touch the EU scope?** Check where the system is placed on the market or put into service, where the deployer is established, and whether the system's output is used in the EU (Article 2). A call's telephone channel alone does not settle territorial scope.
4. **Could the agent be high-risk under Article 6 and Annex III, or has your organization changed an existing system's intended purpose or made a substantial modification?** Stop and get a use-case-specific legal classification. The high-risk deployer duties are not interchangeable with Article 50 transparency, and this checklist does not cover a full high-risk compliance program.

Recital 13 provides context for the role-based approach; Article 3 contains the operative provider and deployer definitions. Article 26 sets out deployer duties for high-risk systems. Neither a CPaaS contract nor a dashboard toggle decides the legal classification for you.

## 2. Six controls to review for customer-facing AI calls

These six lines combine direct duties where they apply with practical procurement and operating controls. They are not six universal statutory duties imposed on every voice-agent deployer: several requirements below attach specifically to high-risk systems or to providers. Confirm the legal basis and scope for your deployment.

| Control to review | Legal context to confirm | Tenant-side action |
| - | - | - |
| **1. Tell the caller when they are interacting with AI.** Give a clear spoken notice before the AI handles the conversation when required for your deployment. | Article 50(1) places a design-and-information duty on providers of systems intended to interact directly with people. It is not a general spoken-notice duty on every deployer. Article 50 gives deployers transparency duties in defined cases, and other laws may apply; confirm which rules cover your calls. | Choose accurate notice text, decide which calls it applies to, enable the tenant's disclosure setting, and test the opening audio. A notice is not, by itself, consent to recording or another processing purpose. |
| **2. Provide a human-oversight route.** Decide how a caller can reach a qualified person when the agent cannot safely or usefully continue. | Article 26(2) requires deployers of high-risk systems to assign human oversight to people with the necessary competence, training, authority, and support. Do not treat a fallback path as a universal Article 50 requirement. | Set a staffed escalation destination, define when the agent must hand off, and test that a caller reaches a person. For high-risk use, document the oversight assignment and authority. |
| **3. Keep the documentation and records your role requires.** Obtain the provider's instructions and technical information relevant to your use; preserve your configuration and change history. | The provider prepares technical documentation under Article 11. Article 26(6) requires deployers of high-risk systems to keep automatically generated logs under their control for an appropriate period of at least six months, unless Union or national law provides otherwise. GDPR storage limitation still matters. | Ask the provider for the applicable documentation and instructions. Retain the agent version, approved configuration, oversight assignment, and relevant call evidence for a justified period; restrict access and set deletion rules. Do not assume every voice transcript must be retained for six months. |
| **4. Monitor operation and record incidents.** Define how staff identify and escalate failures, unexpected behavior, and possible serious incidents. | For high-risk systems, Article 26(5) requires monitoring in line with the instructions and specified action if risks or serious incidents arise, including informing the provider or distributor and, where applicable, authorities. An incident register is a useful operating control, not a new universal AI Act log duty. | Record the issue, affected agent version, call reference, decision, owner, and follow-up. Set a route to pause use and notify the provider when required. Keep personal data out of incident notes unless necessary. |
| **5. Verify quality before and after launch.** Test the agent against representative call scenarios and review whether its answers and handoffs remain suitable for the stated purpose. | The AI Act's quality-management system in Article 17 is a **provider** obligation. For your organization, GDPR accountability, accuracy, security, and (where needed) impact-assessment duties may inform the controls you require and operate. | Set acceptance criteria, review evaluation results, sample calls lawfully, investigate failures, and require corrective action before changing the live agent. Ask the provider how its quality process and release evidence apply to the system you buy. |
| **6. Check deployer-side transparency.** Identify any use where the Act assigns you a specific notice duty, and keep that notice distinct from your general AI voice introduction. | Article 50(3) and (4) assign deployer transparency duties in defined cases, including specified emotion-recognition or biometric-categorisation systems and certain deepfake or public-interest text outputs. They do not create a blanket notice duty for every AI voice call. Article 26(7) separately requires an employer deploying a high-risk system in the workplace to inform workers and their representatives before use. GDPR Articles 13 and 14 govern privacy information where applicable. | Identify the controller and processor roles, purposes, recipients, retention, and contact route in your privacy materials. Inform staff where required, and keep any applicable AI notice distinct from recording consent and the privacy notice. |

## 3. Map each control to a tenant-owned platform surface

A dashboard surface helps you configure or review a control; it does not make the legal decision or activate a complete compliance posture for you. Check the effective setting and the records for your own workspace.

| Control | Tenant-owned control to configure or review | What to verify |
| - | - | - |
| Caller disclosure | In **Settings → Compliance → AI Disclosure**, enable the applicable EU AI Act rule and the master **Enabled by default** setting; review the voice intro text or audio. See [AI-disclosure setup](/guides/ai-disclosure-setup) and [Article 50 transparency](/compliance/eu-ai-act). | Place a test call and confirm the disclosure plays before the agent begins. Disclosure settings are off until your organization enables them. |
| Human oversight | Configure the agent's human handoff destination and escalation conditions in the [Agents dashboard](/agents/human-in-the-loop-oversight). | Test a live or test call through the handoff path, including the staffed destination and what happens when it is unavailable. |
| Documentation and retention | Review call history and recordings in **Voice → Calls → Active**; open a call's detail sheet for its transcript and timeline. Review analysis in [Voice → Intelligence](/guides/voice-intelligence-trends). Apply your workspace's retention and access settings to the records you choose to keep. | Confirm the evidence you need is available, who can access it, the retention period, and the deletion process. These surfaces do not decide the lawful retention period. |
| Incident and change records | Review the call record and associated voice-intelligence evidence; use the [agent version history](/agents/agent-versions) to identify which agent configuration was active. | Ensure an incident can be tied to a call, agent version, owner, and follow-up decision. Maintain your incident response and notification process. |
| Quality management | Use the tenant's agent evaluation and review workflows, and retain the relevant evaluation outcome with the approved [agent version](/agents/agent-versions). | Record acceptance criteria, test results, sampling decisions, corrective actions, and approvals before promotion. |
| Caller and worker transparency | Maintain your tenant's caller notice, privacy information, and any required staff communications alongside the [AI-disclosure settings](/compliance/ai-disclosure-settings). | Make sure the spoken notice, privacy information, recording announcement, and internal instructions describe distinct purposes accurately. |

For GDPR, also assess the call's personal-data purposes, lawful basis, controller/processor allocation, data minimization, access, security, and retention. Complete a data-protection impact assessment where the processing is likely to result in high risk. The [GDPR posture guide](/compliance/gdpr-posture-guide) covers those tenant decisions; AI disclosure does not replace them.

## 4. What Devotel Orbit provides and what your organization owns

| Devotel Orbit provides | Your organization owns |
| - | - |
| Tenant-scoped AI-disclosure settings, including voice-intro configuration and controls that must be enabled by the tenant. | Determining whether the Act applies, whether your organization is a deployer or also a provider, and whether the system is high-risk. |
| Agent handoff and human-oversight configuration surfaces, call history, voice-intelligence views, and agent version history. | Choosing the right caller notice, staffing and testing the human route, and deciding which calls, analyses, and records to retain. |
| Platform records and configuration history that can support review of a deployment. | Setting lawful purposes, GDPR notices and roles, access and retention periods, quality acceptance criteria, incident handling, and any required regulator or provider notifications. |
| Documentation describing the shipped controls and their behavior. | Requesting and assessing provider technical documentation and instructions, maintaining your deployment evidence, and obtaining legal advice for your use case. |

The platform supplies controls and records; it does not make your organization compliant or take ownership of your regulatory decisions. Some of the controls above are tenant choices, not automatic platform guarantees.

## Procurement review before launch

* Confirm the system, intended use, EU connection, and your organization's role with counsel.
* Ask the provider for the system instructions, technical information, known limitations, and evidence relevant to your deployment.
* Enable and test the spoken AI notice; keep it separate from recording consent and the GDPR privacy notice.
* Assign a staffed human route and test failure and escalation cases.
* Set agent-version approval, evaluation, call-evidence access, and retention processes before launch.
* Define monitoring, incident ownership, provider escalation, and any required notifications.
* Re-run the review when the agent's purpose, model, prompt, voice, handoff, or data use changes.

This checklist is limited to CPaaS telephone and AI voice-agent deployments. It does not classify your system, replace qualified legal advice, or cover the full EU AI Act or GDPR program.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.