Your obligations as Deployer under the EU AI Act
Client guide — July 2026
Under the EU AI Act, Omilia acts as Provider of the AI systems listed in this guide. You, as our client, act as Deployer when you put these systems into operation in your own organisation. Provider and Deployer obligations are legally distinct and both must be fulfilled for the deployment to be compliant. This guide sets out what is expected of you as Deployer, organised by the risk tier of the product(s) you use.
Omilia provides the technical capability. You decide the words. Everywhere this guide refers to a disclosure, a consent flow, or wording shown to your end-users, Omilia supplies the mechanism, not the message. The specific language, tone, and consent design are yours to set with your own legal and product teams. Nothing below should be read as Omilia dictating what you say to your customers.
How to Use This Guide
Find your product(s) below, then go to the matching section. If you use products across more than one tier, all relevant sections apply.
|
Product |
Risk Tier |
Section to Follow |
|
OCP Voice, Chat & Drive-Thru · Neural TTS · Self-Learning CX Agents |
Limited Risk |
Section A |
|
Agent Assist · Workforce AI · VB Blocklisting / Anti-Fraud Bundle · TalkGuard (Blocklist · Age/Gender Detection layers) |
High Risk |
Section B |
|
VB Authentication (IVR) · Pathfinder · Testing Studio · OptimizeIQ · OCP Developer CoPilot |
Minimal Risk |
Section C |
Section A — Limited Risk Products
Applies to: OCP Voice, Chat & Drive-Thru · Neural TTS · Self-Learning CX Agents
|
Obligation |
Deployer Action Required |
|
Art. 50(1) AI-interaction disclosure |
Activate and configure the disclosure before go-live. Agree final wording with your legal team. Ensure end-users are informed before or at the point of first interaction. |
|
Art. 50(2) Synthetic audio marking |
Do not remove, strip, or suppress the machine-readable watermark on TTS output, including in your telephony, call-recording, or downstream storage infrastructure. |
|
Art. 50(4) Synthetic content labelling |
If you repurpose or redistribute Omilia-generated synthetic audio outside the original customer interaction (for example in marketing use), label it as AI-generated. The EU Code of Practice on Transparency of AI-Generated Content recommends a standard icon or equivalent label for this, plus keeping a short internal record of how you apply it. Not mandatory to use the Code's icon specifically, but it's the recognised reference point regulators will expect you to be aware of. |
|
Art. 14 Human-in-the-loop (Self-Learning CX Agents only) |
Keep your human-approval gate active and non-bypassable for any self-learning update path. This condition is what keeps the product in the Limited Risk tier. |
Section B — High Risk Products
Applies to: Agent Assist · Workforce AI · VB Blocklisting / Anti-Fraud Bundle · TalkGuard (Blocklist and Age/Gender Detection layers)
|
Obligation |
Deployer Action Required |
|
Art. 26(1) Use per instructions |
Operate the system strictly within the intended purpose and configuration set out in Omilia's Instructions for Use. |
|
Art. 26(2) Human oversight |
Assign oversight to named staff with the competence, training, and authority to intervene in or override system outputs. |
|
Art. 26(4) Input data quality |
Where you control the input data, ensure it is relevant and sufficiently representative for the system's intended purpose. |
|
Art. 26(5) Monitoring & incident escalation |
Monitor operation against the Instructions for Use. If you have reason to believe the system presents a risk, notify Omilia and your market surveillance authority without undue delay and suspend use. Report serious incidents to Omilia immediately. |
|
Art. 26(6) Log retention |
Retain system-generated logs under your control for at least 6 months, or longer where your own sector or data-protection rules require it. |
|
Worker notification (employee-monitoring products) |
If you are an employer using Agent Assist or Workforce AI, inform workers' representatives and affected employees before putting the system into service. |
|
GDPR Art. 35 Data Protection Impact Assessment |
Complete your own DPIA where required. Omilia's DPA Annex 1 provides the processor-side information you need for this. |
|
Art. 27 Fundamental Rights Impact Assessment |
Only required if you are a public-body deployer, a private entity providing public services, or deploying for Annex III §5(b)/(c) use cases (creditworthiness, insurance risk pricing). Not triggered by standard commercial use of Omilia's classified high-risk products — confirm with your own counsel if your use case differs. |
|
Art. 26(12) Cooperation with authorities |
Cooperate with your national market surveillance authority on any AI Act enquiry relating to the system. |
|
Art. 50(3) Biometric categorisation disclosure (TalkGuard Age/Gender Detection) |
Suggested wording: "This service uses automated voice-analysis technology to estimate characteristics such as age range or gender, for the purpose of [state purpose, e.g. fraud detection / call routing]. This analysis does not identify you personally and is separate from any assessment of your emotional state." |
|
Art. 50(3) Voice-biometric processing disclosure (Anti-Fraud / VB Blocklisting) |
Suggested wording): "This call may be processed using voice-biometric technology to help detect fraudulent activity. This technology does not identify you personally and does not assess your emotional state." |
Section C — Minimal Risk Products
Applies to: VB Authentication (IVR) · Pathfinder · Testing Studio · OptimizeIQ · OCP Developer CoPilot
-
No mandatory EU AI Act obligations apply to these products under their current classification.
-
Exception — VB Authentication: the Art. 50(3) biometric-categorisation disclosure obligation applies independently of the risk tier. Activate this disclosure the same way as for Limited Risk products.
-
Suggested wording for VB Authentication (draft, pending Legal sign-off, tailor to your context): "This call may be processed using voice-biometric technology to verify your identity. This technology does not identify you personally beyond that verification and does not assess your emotional state."
-
Good practice (voluntary): keep an internal record of use consistent with your own AI governance policy, and nominate the same point of contact referenced below.
Deadlines at a Glance
|
Date |
Deployer Action Due |
Applies To |
|
2 Aug 2026 |
Activate Art. 50(1)/(3)/(4) disclosures |
All Limited Risk products, plus VB Authentication (biometric disclosure) |
|
2 Dec 2026 |
Confirm non-suppression of Art. 50(2) watermark |
Existing Neural TTS deployments - Deadline for watermarking labelling is 2 December 2026 |
|
2 Dec 2027 |
Full Art. 26 / Art. 27 deployer programme operational |
Agent Assist, Workforce AI, VB Blocklisting / Anti-Fraud Bundle, TalkGuard high-risk layers |
What Omilia Provides in Support
-
DPA Article 26 assistance clause: Omilia assists you with DPIA support and regulatory enquiry responses.
-
Incident notification: Omilia notifies you of personal data breaches within 24 hours; AI Act serious incidents follow the same pathway.
-
Audit rights: you retain the right to audit Omilia's compliance with the data protection and security obligations underpinning these products.
-
Instructions for Use and technical documentation issued per high-risk product ahead of the relevant deadline (2 December 2027).
Every Deployment — Regardless of Tier
Standard vendor-relationship items apply as usual: nominate an internal AI Act point of contact, keep a record of your configuration, complete AI-literacy training for relevant staff (Art. 4), and execute the DPA if you haven't already. None of that is Omilia-specific, it's the same baseline you'd apply to any vendor.
This document reflects Omilia's understanding of deployer obligations as of the date indicated and does not constitute legal advice. Deployers should seek independent legal counsel regarding their own compliance obligations. Classification: Confidential — for Deployer internal use only. Contact: corporate-grc@omilia.com