Do AI voice agents and phone bots need disclosure under the EU AI Act?
Last updated 30 July 2026
Voice is the channel where AI disclosure fails most naturally: there is no screen, no badge, no header line — if the agent doesn’t say it, the caller doesn’t know. And modern speech synthesis is good enough that “obvious to the user” is a hard argument to win. Short answer: yes, disclose, in the greeting.
Why voice agents are squarely in scope
Article 50(1) covers AI systems intended to interact directly with natural persons. A voice agent answering your support line or making outbound calls is the paradigm case — the interaction is real-time, conversational, and with a natural person. The only exemption is where the AI nature is obvious to a reasonably well-informed person. A decade ago, robotic IVR voices arguably qualified; today’s neural voices with fillers, laughter and interruptions do not. Do not build your compliance on the hope that users can tell.
Inbound calls (users call you)
Put the disclosure in the greeting, before the agent starts handling the request:
- “Thanks for calling [Company]. You’re speaking with our automated AI assistant — I can help with most questions, or say ‘agent’ to reach a person.”
This satisfies Article 50(5)’s “at the latest at the time of the first interaction” requirement and doubles as good UX: callers who want a human bail out early instead of getting angry three minutes in.
Outbound calls (your AI calls users)
Outbound is stricter in practice. The recipient has no context at all, so the AI must identify itself and the company immediately:
- “Hi, this is an automated AI assistant calling on behalf of [Company] about your appointment on Thursday.”
Note that outbound AI calling also intersects with ePrivacy and national telemarketing rules (consent, calling-line identification), which apply independently of the AI Act.
Cloned and celebrity-style voices: the deep-fake angle
If your agent speaks with a voice cloned from a real person, you are generating synthetic audio that appreciably resembles an existing person — that is a deep fake under Article 3(60), and Article 50(4) requires deployers to disclose that the content has been artificially generated or manipulated. A generic synthetic voice avoids this; a cloned one adds a second, separate disclosure duty. See labelling AI-generated content for how 50(2) marking and 50(4) disclosure differ.
Who is responsible: you or your voice-AI vendor?
If you buy a voice-agent platform and deploy it on your phone number, you are typically the deployer, and the practical duty to ensure callers are informed lands on you — the vendor can’t say the greeting for you. If you build and sell the agent, you are the provider with design-level duties. The provider/deployer split is covered in is my chatbot covered?, and it applies to non-EU companies serving EU callers too — see the extraterritorial scope guide.
Practical checklist for voice
- Disclosure sentence in every greeting (inbound) and opener (outbound), containing “AI” or “automated.”
- A working escape hatch to a human, honored promptly.
- No human name + human-sounding persona without the AI disclosure alongside it.
- If using voice cloning of a real person: explicit deep-fake disclosure and the person’s consent (the latter under other laws).
- Log the greeting script and rollout date — evidence of compliance from 2 August 2026 (the date is firm; see was the AI Act delayed?).
Not sure which paragraphs of Article 50 apply to your stack? Run the free compliance checker — it takes about two minutes.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check