Regulation

European Electronic Communications Code and AI use cases

Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.

Read the source text (European Union)

Depends on design under the EU AI Act

The tier depends on how the system is used, for example whether it decides on access to an essential service.

  • Agentic AI for autonomous, intent based network operations

    Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk; Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. Loops that only optimise performance or capacity are usually not safety components, but a loop that protects physical integrity or life safety services can be, so operators should assess each closed loop and document the outcome.

  • AI agent for network outage detection and customer communication

    The customer facing agent is limited risk with an Article 50 duty to disclose AI. AI used as a safety component in the management and operation of critical digital infrastructure is high risk under Annex III point 2, so the classification depends on whether the detection part acts on the network or only informs people.

  • AI assistant for telecom plan upgrades, add ons and sales

    A sales assistant is limited risk with an Article 50 duty to disclose AI. If it assesses the creditworthiness of individuals for devices on credit, that part is high risk under Annex III point 5(b), so keep credit decisions in the existing governed process. Selling that uses manipulative or deceptive techniques, or exploits a customer's age, disability or economic situation, to materially distort a purchase decision in a way likely to cause significant harm is prohibited under Article 5(1)(a) and (b).

  • AI for telecom churn prediction and retention offers

    Churn scoring and offer selection for marketing are not listed in Annex III, so a back office design that only scores customers and prompts human advisors is minimal risk, with no specific obligations. When an AI agent delivers the offer to the customer in chat, messaging or voice, the system is limited risk: Article 50 requires telling customers they are dealing with AI. A design that used manipulative techniques or exploited vulnerabilities to keep customers from leaving could fall under the Article 5 prohibitions. GDPR rules on profiling and the right to object to direct marketing (Article 21) apply in full.

  • AI for telecom fraud detection (SIM swap, IRSF and Wangiri)

    Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.

Limited risk (transparency) under the EU AI Act

People must be told they are dealing with AI, and generated content must be identifiable (Article 50).

  • AI agent for device and connectivity troubleshooting on voice and chat

    A customer facing troubleshooting agent must tell people they are interacting with AI unless that is obvious (Article 50). It is not high risk as long as it is not used as a safety component in the management and operation of critical digital infrastructure (Annex III, point 2); running line tests and resets for one customer's service does not make it one.

  • AI agent for telecom bill explanation and billing disputes

    A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1)). Explaining bills, correcting clear errors and opening disputes are not listed in Annex III. The tier changes only if the system is also used to evaluate customers' creditworthiness, for example to set credit limits, which Annex III point 5(b) lists as high risk.

  • AI assistant for B2B telecom quoting, sales and service

    Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Quoting, sales support and service for business customers are not listed in Annex III. The use would become high risk under Annex III point 5(b) only if the assistant itself evaluated the creditworthiness of a natural person, such as a sole trader, to decide whether to offer a contract.

  • AI assistant for telecom order to activation and eSIM onboarding

    A customer facing assistant must disclose that it is AI (Article 50). Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from remote biometric identification in Annex III point 1(a); creditworthiness assessment of individuals (Annex III point 5(b)) would be high risk and belongs in a separate governed process.

  • AI assistant for telecom retail stores, from associate copilot to digital human kiosk

    A digital human or kiosk that talks to customers must be designed so that they are told they are interacting with an AI system (Article 50(1)). An associate copilot over product content is not listed in Annex III and is minimal risk. Inferring the emotions of employees at work is prohibited (Article 5(1)(f)); emotion recognition of customers by camera is high risk under Annex III point 1(c), biometric categorisation by sensitive or protected attributes is high risk under Annex III point 1(b), and categorisation that infers race, political opinions, religion or sexual orientation is prohibited under Article 5(1)(g). Both need separate legal review.

Minimal risk under the EU AI Act

No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.

  • AI spam and scam call blocking for mobile and landline subscribers

    Scoring, blocking and labelling calls is not listed in Annex III, is not a prohibited practice under Article 5, and the system does not interact with people or generate content, so Article 50 does not apply. A conversational scambaiting agent such as O2's Daisy talks to callers with a synthetic voice, which raises separate Article 50 transparency questions and should be assessed on its own.