Skip to content
Novot AI
NLBook a call
← Back to knowledge base

Which risk category does your customer-contact AI fall into?

Ordinary customer contact — a chatbot, AI on WhatsApp or an AI phone agent that answers questions and books appointments — almost always falls into the limited-risk category: your main duty is to state clearly that people are talking to AI. It only becomes high risk when the AI helps decide something that really affects people, such as filtering job applications, assessing creditworthiness or access to essential services. You make that classification yourself, per application, and you have to be able to explain it.

Published on

Why the law works with four categories instead of one rulebook

The AI Act does not impose the same duties on everyone. The law first looks at what an AI system does and how much harm it can cause. Only then does it decide how much you have to arrange. The Dutch Data Protection Authority, which plays a central role in supervision here, puts it plainly: the higher the risk to people or to society, the stricter the rules your organisation has to deal with.

That is good news for most business owners. An AI that answers questions about opening hours, forwards a quote request or books an appointment is not in the same class as a system that decides whether someone gets a loan. But it also means you have to work out for yourself where your application lands. No letter arrives. There is no desk that hands you a stamp. The classification is a judgement you make and one you have to be able to explain if someone asks.

The four categories are: unacceptable risk, high risk, limited risk (also called the transparency category) and minimal risk. They are not set out in the legal text as four labelled boxes, but they follow from its structure: prohibited practices in Article 5, high-risk systems in Article 6 with Annex III, transparency duties in Article 50, and everything else.

Category one: what you may not do at all

At the top sits what is banned outright. The European Commission lists nine practices the regulation prohibits. They include harmful AI-based manipulation and deception, harmful exploitation of people's vulnerabilities, social scoring, and predicting criminal behaviour of individuals. These bans are in Article 5 of the regulation.

For an ordinary business running a chatbot or an AI phone agent this is rarely a real risk, but it is not purely theoretical either. The line sits at manipulation. An AI assistant that deliberately misleads people about what it is, that pressures vulnerable groups, or that plays on a disability or an age to push someone into a purchase, is heading into dangerous territory. An AI that says honestly what it is and simply answers questions comes nowhere near it.

Worth knowing: you cannot buy your way out of this category with a good processing agreement or a clear notice. Banned is banned. There is no version where extra documentation makes it acceptable after all.

Category two: when your AI is high risk

High risk is not a matter of feeling. It is a list. Article 6 of the regulation states that AI systems named in Annex III count as high risk. There is a second route as well: AI that sits as a safety component inside a product already covered by European product legislation, such as medical devices or lifts.

Annex III names areas including biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice. For a normal small or medium-sized business, two of them genuinely matter.

Recruitment and worker management

This is the most likely way an ordinary business ends up in the high category, and it is almost never the customer chatbot. Annex III literally names AI intended to be used for recruiting or selecting people, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. AI that helps decide on promotion, dismissal or task allocation falls under the same point.

That touches customer contact more often than you would think. Point the same AI inbox at job applications and let it sort incoming replies by suitability, and one system is doing two things: answering customer questions (transparency category) and filtering candidates (potentially high risk). The category attaches to the use, not to the brand of the software.

Creditworthiness and access to essential services

Annex III also names AI that evaluates the creditworthiness of natural persons or establishes a credit score. The same goes for AI that assesses who gets access to essential services, and for risk assessment and pricing in life and health insurance. If you work in financial services, rental housing, healthcare or energy, and you let AI weigh in on who is helped and who is not, you need to look at this seriously.

Note the word evaluate. An AI that neatly copies an application form into your system evaluates nothing. An AI that turns that same application into a score a staff member acts on does.

There is a way out of Annex III, but it is narrow

Article 6(3) contains an escape clause many business owners do not know about. If your application formally falls into an Annex III area but does not materially influence the outcome of a decision, it does not count as a high-risk system. The law names four situations: the system performs a narrow procedural task, it improves the result of work a human has already completed, it flags deviations from earlier decision patterns without replacing or influencing the human assessment, or it only does preparatory work.

Two warnings. First: as soon as the system profiles people, the exception does not apply. Profiling is always high risk within an Annex III area. Second: this is not a sentence you write down after which you are finished. You have to be able to show that the system does not steer the outcome. "A staff member still looks at it" is too thin if that person always takes the AI's suggestion in practice.

Why ordinary customer contact usually lands in the transparency category

If your AI stays on the side of answering questions, giving information, transferring calls and booking appointments, you are almost always in the third category: limited risk. There, it all comes down to one thing. People must know they are talking to a machine. The European Commission explains the core of it this way: with AI systems such as chatbots, people must be told they are interacting with a machine so they can make an informed decision.

That is the whole category. No conformity assessment, no technical documentation, no registration in a European database. But a clear notice, in time, in plain language. Article 50 covers this and requires the information to be given at the latest at the time of the first interaction, in a clear and distinguishable way. At the bottom of your privacy statement is therefore too late.

In practice, for the three channels where small businesses actually are:

  • Chat on your site. The first message says it is an AI assistant, and how someone reaches a human.
  • WhatsApp and email. The first reply in a new conversation makes clear that an AI is reading along or answering.
  • Phone. The opening of the call says so, not only when the caller asks.

This category also covers AI-generated content you publish, and images or audio that look or sound real. If you use AI to create a customer story or to imitate a voice, it needs a label.

Category four: minimal risk is not the same as no rules

The fourth and by far largest group is minimal risk. Spam filters, product recommendations in a webshop, stock forecasting, summaries for internal use: the regulation imposes no specific duties here. For many businesses this is where most of their AI sits.

Two things not to forget. Article 4 of the regulation deals with AI literacy and applies regardless of category: you take measures to support the AI knowledge of the people who work with those systems. And the GDPR remains fully in force. If your AI processes personal data, then a legal basis, data minimisation, retention periods and the rights of data subjects all still apply. The AI Act does not replace privacy law, it comes on top of it.

The four categories side by side

The four risk categories of the AI Act and what is expected in each of them from a business owner deploying AI
CategoryTypical exampleWhat is expected of you
Unacceptable riskManipulation, exploiting vulnerability, social scoringNot allowed. No amount of documentation or notice makes it possible after all.
High riskAI that filters job applications, assesses creditworthiness or decides on access to essential servicesHeavy duties: risk management, data quality, technical documentation, logging, human oversight, information to users. Put your own brand name on it or change it substantially and you move up into the provider role with the full set of duties.
Limited risk (transparency)Chatbot, AI phone agent, AI replies on WhatsApp and email, AI-generated contentState that it is AI, at the latest at the first interaction, clearly and distinguishably. Label AI-generated content.
Minimal riskSpam filter, product recommendations, internal summariesNo specific duties under the regulation. AI literacy and the GDPR still apply.

How to make and record the assessment yourself

Nobody classifies your system for you. Do it in this order, per application and not per supplier.

  1. Write down what the system does. Not "AI for customer contact", but: reads incoming WhatsApp messages, answers questions about delivery times and returns, books appointments, passes the rest to a staff member.
  2. Check the prohibited list. Is there anything in there that misleads or pressures people? Then stop.
  3. Walk through Annex III. Does one of the areas touch your use? Especially recruitment, personnel decisions, creditworthiness and access to services.
  4. If yes: test against Article 6(3). Does the system materially influence the outcome? Does it profile people? When in doubt, assume high risk.
  5. If no: does the customer talk to the AI? Then you are in the transparency category and you arrange the notice.
  6. Record the result. One page per system: what it does, which category, why, who decided and when. If the use changes, you run through it again.

That last point is the one most often skipped. The assessment is not the problem; the absence of proof that you made it is. If the use changes, for instance because you suddenly point the same AI at your vacancy mailbox, the category may change with it.

What it means if you land in the high category

If you end up at high risk, the playing field changes. The heaviest duties sit with the provider, the party that builds the system and puts it on the market: a risk management system, requirements for training data, technical documentation, automatic logging, human oversight that actually works, accuracy and robustness, a conformity assessment and registration.

As the party deploying the system you have a lighter but far from empty package. You use it according to the instructions. You make sure the input data fits the purpose. You appoint people to supervise who have the knowledge and the authority to step in. You keep the logs. In recruitment and personnel decisions you inform the workers concerned. And if you notice that the system creates a risk, you report it to the provider and stop using it if necessary.

There is one trap you need to know about. The line between provider and deployer is not fixed. Put your own brand name on a supplier's high-risk system, or change it substantially or change its intended purpose, and under Article 25 you are treated as the provider yourself, with all the duties that come with it. So anyone giving their AI agent its own name and house style should know which category that system is in before doing so.

For a smaller business the sober conclusion is usually this: if you are heading towards high risk for something that is not a core process, adjusting the use is cheaper than building out the full set of duties. Have AI sort applications by arrival and completeness rather than by suitability, and you are in a different regime.

From when do which rules apply

The categories exist, but they do not all take effect at once. The prohibited practices and the transparency rules already apply. The rules for high-risk systems have been postponed: they apply from 2 December 2027 for the systems in Annex III, and from 2 August 2028 for AI embedded in physical products such as medical devices, toys and lifts. If you come across Dutch guidance still naming a different date for high risk, it is out of date.

Postponement is not cancellation, and it is no reason to put off the assessment. If you set up a system now that turns out to be high risk a year from now, you pay for it in rebuilding costs. On top of that, the GDPR runs on its own clock: a data protection impact assessment for a system with a high privacy risk has to be done now, before you put it into use.

What you can do this week

Make a list of every place where AI does something with customer or personal data. Chat, email, phone, calendar, job applications, quotes. For each line, note what the system decides or proposes, and what a human still does afterwards. Then walk through the steps above and write down the category with a reason.

In most cases you will land in the transparency category and the work is small: a notice at the start of every conversation, an explanation of what the AI does and does not do, and a clear route to a human. If you land somewhere else, you know that now, rather than after an applicant or a customer starts asking questions about it. That is exactly what the risk-based design of the law is for: most of the work ends up where people actually have something to lose.

See what Novot AI can do for your business.

Book a call