Compliance & AI Act
The EU AI Act in the call center: what it really means for agent evaluation
Regulation (EU) 2024/1689 — the EU AI Act — has stopped being a conference topic. It is binding law that directly affects call centers using AI to evaluate agents’ work. And in June 2026 the calendar changed: the “Digital Omnibus on AI” moved the high-risk compliance date from 2 August 2026 to 2 December 2027. That is extra runway, not a repeal — several duties bind you already today. Here is what applies when, and what to do with the time.
Why call evaluation is a high-risk system
Annex III of the AI Act, point 4(b), lists systems “intended to be used to monitor and evaluate the performance and behaviour of persons in work-related relationships”. A system that transcribes agents’ calls, scores them and aggregates results per person matches that definition literally — regardless of what the vendor calls it.
Be suspicious of vendors claiming their employee-evaluation tool is “not a high-risk system”. That classification is not a marketing choice; it follows from the product’s intended purpose. And note what the 2026 amendment did not do: it did not remove employee evaluation from Annex III. Agent scoring remains high-risk — only the date moved.
The calendar after the Digital Omnibus: what applies when
The AI Act entered into force on 1 August 2024 with staggered application dates. In 2026 the EU revised that calendar: political agreement on the Digital Omnibus was reached on 7 May 2026, the European Parliament endorsed it on 16 June and the Council gave its final approval on 29 June 2026. The result for call centers:
- 2 February 2025 — already binding. Prohibited practices (Art. 5), including the ban on inferring employees’ emotions from biometric data, and the AI literacy duty (Art. 4).
- 2 August 2025 — already binding. Governance rules and obligations for providers of general-purpose AI models.
- 2 August 2026. Article 50 transparency duties apply and become enforceable — relevant if you also run voicebots or AI chat: customers must be told they are talking to a machine. Breaches can draw fines of up to €15 million or 3% of worldwide annual turnover. Generative systems already on the market get until 2 December 2026 for machine-readable marking of AI-generated content.
- 2 December 2027. The full high-risk regime for stand-alone Annex III systems — including monitoring and evaluation of employees, so AI agent scoring. This is the date the omnibus moved; it was originally 2 August 2026.
- 2 August 2028. High-risk obligations for AI embedded in regulated products (Annex I).
Your duties as a deployer
A company deploying an AI evaluation system is a “deployer” in AI Act terms — with its own obligations that cannot be delegated to the vendor. For Annex III systems these obligations become enforceable on 2 December 2027, but two rows in this table already bind you today, and one is required by the GDPR regardless of any AI Act date:
| Obligation | Legal basis | What it means in practice |
|---|---|---|
| Inform employees before go-live | Art. 26(7) AI Act | Agents and their representatives must know they are subject to an AI system’s evaluation before it is switched on. In Poland, Art. 22³ of the Labour Code adds its own notice requirements for workplace monitoring. |
| Human oversight | Art. 26(2) AI Act | Trained people review the scores and have real authority to question and correct them. AI scoring supports management decisions; it does not replace them. |
| Adequate input data | Art. 26(4) AI Act | Recordings fed into the system must be of appropriate quality, relevant and consistent with the system’s intended purpose. |
| Usage logs | Art. 26(6) AI Act | Keep automatically generated system logs for at least 6 months — longer where other EU or national law requires it. |
| DPIA | Art. 35 GDPR + Art. 26(9) AI Act | Run a data protection impact assessment before switching monitoring on — this is GDPR law and applies now, not in 2027. The provider must supply the information you need for it. |
| AI literacy | Art. 4 AI Act | Managers and HR working with the results must understand how the system works and where its limits are. Binding since 2 February 2025; the 2026 omnibus softened it to a duty to support AI literacy rather than guarantee it. |
The red line: emotions from voice
Art. 5(1)(f) of the AI Act bans inferring employees’ emotions in the workplace from biometric data — and voice is biometric data. Unlike the high-risk regime, this prohibition was not postponed: it has applied since 2 February 2025 and sits in the highest penalty tier, up to €35 million or 7% of worldwide annual turnover.
The practical takeaway: a call evaluation system should not analyze agents’ tone of voice or prosody, and configuring a criterion like “rate the agent’s emotional attitude” should be technically impossible, not merely contractually forbidden.
A safe architecture looks like this: language models receive transcript text only. Evaluating an agent’s emotions or state of mind isn’t “switched off” — it is unfeasible.
What the postponement does not change
Treating 2 December 2027 as “nothing to do until then” would be the wrong reading. Three things apply with full force today:
- The GDPR. Call recordings are personal data of both agents and customers. Lawful basis, retention limits, processor agreements and the DPIA for systematic employee monitoring are current obligations, not future ones.
- The Art. 5 prohibitions. Emotion recognition at work from biometric data has been banned since February 2025 — with the AI Act’s highest fines attached.
- National labour law. Notice and consultation duties for workplace monitoring exist independently of the AI Act.
There is also a practical argument: a compliant deployment of agent evaluation — vendor selection, DPIA, employee communication, criteria calibration — realistically takes months. The 16 extra months are enough to do it properly once, not a reason to start in autumn 2027.
What to demand from your vendor
- An explicit classification of the system under the AI Act with reasoning — not an avoidance strategy.
- Explainable scores — every result must trace back to a specific call and a transcript quote, so a human can verify it.
- A technical block on emotion analysis of employees (a configuration validator), in line with Art. 5.
- A provider compliance plan — from labeling AI-generated content, through a risk register and technical documentation, to conformity assessment, the EU declaration and CE marking.
- Support with your own duties — an employee notice template, DPIA input data, training materials.
How CallSea approaches this
CallSea deliberately classifies itself as a high-risk system and follows a phased compliance plan mapped all the way to CE marking and registration in the EU AI database. Art. 5 guardrails are active today: a validator blocks criteria inferring agents’ emotions, and models evaluate only the text produced by call transcription — tone of voice never reaches the scoring layer. Every result in call quality scoring traces back to a specific call and a transcript quote, which is exactly the explainability a human overseer needs. Clients receive a deployment pack: the employee notice template, DPIA input data and AI literacy materials.
Frequently asked questions
Is AI-based call scoring of agents a high-risk system under the EU AI Act?
Yes. Annex III, point 4(b) of the AI Act covers systems used to monitor and evaluate the performance and behaviour of people in work-related relationships. A tool that transcribes agents’ calls, scores them against criteria and aggregates results per person falls within that description, regardless of the vendor’s marketing label.
When do the EU AI Act high-risk obligations start to apply to call centers?
From 2 December 2027 for stand-alone Annex III systems such as agent evaluation — the Digital Omnibus adopted in June 2026 moved this date from the original 2 August 2026. The ban on emotion recognition at work and the AI literacy duty have applied since 2 February 2025, and Article 50 transparency duties apply from 2 August 2026.
Can AI analyze the tone of voice or emotions of call center agents?
No. Article 5(1)(f) of the AI Act prohibits inferring employees’ emotions from biometric data — and voice is biometric data — except for narrow medical and safety purposes. This ban has applied since 2 February 2025 and carries the highest tier of fines: up to €35 million or 7% of worldwide annual turnover.
Do I need a DPIA before deploying AI call analysis?
Yes. A data protection impact assessment under Art. 35 GDPR is required before you switch on systematic monitoring of employees, and it does not depend on the AI Act calendar. Your vendor is obliged to give you the information needed to carry it out (Art. 13 in conjunction with Art. 26(9) AI Act).
Disclaimer: this article is for information purposes and is not legal advice. It reflects the legal state as of July 2026, including the Digital Omnibus amendments adopted in June 2026. The exact scope of duties depends on your deployment — consult your lawyer or DPO.