
AI This article was created with the help of AI.
Key takeaways
Picture a typical field sales team: 25 reps, two to three customer meetings a day, driving time in between. Three AI use cases run in parallel there without you having looked at them separately so far. The AI Act doesn't regulate "AI in sales" across the board: it bans certain practices, sets special requirements for high-risk systems, and establishes transparency rules for certain AI systems - each tied to placing on the market, putting into service, and use.[1] The EU Commission describes this structure as a risk-based approach.[2] That's why the first step isn't a tool list, but separating the cases.
Voice Agents like Vicky and Tim are a good example for the first two cases. They work over a normal phone call, even without an internet connection, and function entirely without transcription. Transcribing a customer meeting is, on the product side, a separate, optional processing step - and therefore also to be assessed separately under the law. Case 3, on the other hand, is not a product feature: whether you analyze performance data in aggregated form is a decision you make yourself as the deploying company. And that decision needs its own review later.
Why the separation matters: each case has its own purpose, different users, and different affected persons. The AI Act ties its rules to the concrete use of an AI system, not to the category of the tool: what counts is the intended purpose - the use for which a system is intended by its provider.[3] If you mix the three cases, you end up reviewing the wrong thing. As a side note, if you're getting started with pre- and post-meeting work via phone call, it's worth a look at CRM updates by phone.
The AI Act defines two central roles. Providers develop an AI system or have it developed and place it on the market under their own name or brand.[3] Deployers use an AI system under their own responsibility, unless the use is part of a personal, non-professional activity. As a sales leader, you run the team that puts the system to use: your company is the deployer, not the provider. This classification decides which obligations land with whom.
Two events force a renewed role review: substantial changes to the system and a changed intended purpose. An example from everyday life: as long as the debrief only serves documentation, the intended purpose stays stable. As soon as you use the same debriefs for company-wide insights, the purpose changes, and the review starts from scratch.
Important distinction: GDPR roles cannot be mapped one to one. Controller and processor are terms of data protection law; provider and deployer are terms of the AI Act. An AI provider can also be a processor under the GDPR, but the two pairs of terms run separately and must not be played off against each other.
The transparency obligations under Art. 50 apply, pursuant to Art. 113, from 2 August 2026. The legal text lets you separate three layers that have different consequences in sales.[5]
The takeaway: no blanket AI label on every follow-up email. An email that a rep reviews from a draft, adapts, and sends out under their own responsibility is not a published text on a matter of public interest. So do not demand AI banners in customer contact without checking the specific case; that creates effort without legal cause.
The information obligations for conversation transcription must be treated separately. They follow the GDPR, not Art. 50: para.[4] 6 expressly leaves other transparency obligations of Union and national law unaffected.[6] Data subjects are entitled to know the purpose, legal basis, storage period and recipients of the processing.[7] A transcript is personal data: a lawful basis, transparency towards participants and deletion periods remain in place even if no recording is stored. In practice, consent under Art. 6(1)(a) GDPR can serve as the legal basis.
On the fine framework: for violations of the transparency obligations for providers and deployers under Art. 50, Art. 99(4) of the AI Regulation provides for fines of up to EUR 15,000,000 or, in the case of companies, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, the lower of the two amounts applies in each case.[8]
Besides the transparency obligations, there are hard limits you must check regardless of the assistant in question. The ban on AI systems for inferring emotions in the workplace and in educational institutions is set out in Art. 5 of the AI Regulation, which has applied since 2 February 2025. Use cases in workforce management, such as AI for managing employees, on the other hand, may be classified as high-risk systems under Annex III and then trigger the considerably stricter obligations of Chapter III, which take effect later than the transparency rules.[9][10]
One distinction deserves particular care: emotion recognition within the meaning of the AI Act infers emotional states from biometric data. Text analysis or conversation statistics are something else: metrics such as speaking shares or qualification criteria mentioned in a transcript are not emotion recognition. Do not equate the two, in either direction.
Two common mistakes happen here. First: an ISO 27001 certification or SOC 2 attestation does not automatically mean clearance under the AI Act; these certifications demonstrate information security, not conformity with the AI legal framework. Second: never assume an AI assistant is automatically high-risk or risk-free. The classification follows from your concrete use case, not from the product category.
Since 2 February 2025, Art. 4 has required providers and deployers to take measures so that their staff and other persons acting on their behalf who work with AI systems have a sufficient level of AI literacy. The provision does not prescribe a specific outcome level: there is no rigid statutory number of hours, no mandatory exam and no universal certificate.[11] What matters is that your team knows where the limits of the assistant lie, and that this knowledge is documented. An editorial example of such training, split by audience:
In addition, put responsibilities in writing: who approves a new use case? Who is the contact for data protection questions? Who trains new reps when they join the team? Record the answers in a short document so that AI literacy in your team does not depend on a single person. That is exactly what Art. 4 requires at its core: appropriate measures that fit the use case, the team and the risk.
In the end, every reviewed use case needs an internal approval that you can fill in and present at the next audit. This overview has proven itself in practice:
For the deadline overview, the legal status is August 2026: the prohibitions under Art. 5 and the AI literacy obligation under Art. 4 have applied since 2 February 2025, and the transparency obligations under Art. 50 since 2 August 2026. The obligations for high-risk use cases, including in employee management, come later; check the exact date against the official legal text before your approval, because Art. 50 has since been amended and not every version online is up to date.[13]
Three review steps deserve their own articles and are only linked here: the DPA contract check with the provider, the consent wording for the in-person conversation consent in the in-person conversation, and a vendor risk review across all AI services in use. But before you tackle these steps comes the approval of your use case, because it determines which of the three reviews even applies.
Vicky and Tim are voice agents for field sales. They work by phone call from your mobile, even without an internet connection, and support you with meeting prep, debrief, and CRM updates. Transcription is not required for this: the agents work fully without it, and transcription remains an optional add-on.[7][12] Email drafts are created only for review and are never sent without your explicit instruction.[12] The provider is ISO 27001 certified and processes data in the EU.[7] You'll find details on usage and setup on the Vicky page, your personal assistant.
This description is deliberately not an AI Act approval: as the deployer, you make the classification of your use case, following the steps in this article. If you'd like to discuss the planned use of Vicky and Tim, talk to Bliro directly. Together you can work out which of the three cases applies to you, which information measures it triggers, and where the limits of your use case lie.