The Act's high-risk obligations apply from 2 August 2026. Most voice AI in production is limited risk, but emergency triage, recruitment, credit, insurance, education and public services are not. What actually applies to a voice agent, where the line falls by industry, and the role trap that turns a buyer into a provider. By Cloudax.
On 2 August 2026 the high-risk chapter of the EU AI Act starts to apply, alongside the Article 50 transparency duties. Most voice AI in production is not high-risk, but the deployments that are sit in emergency triage, recruitment, credit, insurance, education and public services.
Article 50 applies to essentially every conversational AI system on the EU market: tell people they are talking to a machine unless it is obvious, mark synthetic audio in machine-readable form, notify anyone exposed to emotion recognition, and (under Article 4, in force since February 2025) ensure the people operating the system have sufficient AI literacy. In voice, "obvious" is a shrinking defence; the industry has spent two years making agents that do not sound synthetic.
Article 5 has been in force since February 2025 and carries fines of up to €35 million or 7% of worldwide turnover. It prohibits manipulative or deceptive technique that materially distorts behaviour, exploitation of vulnerability arising from age, disability or social and economic situation, emotion inference in the workplace and in education, and biometric categorisation by protected attribute. Accent and voiceprint are biometric data.
High-risk is a list, not a judgement call. Five of the eight Annex III areas are directly relevant to voice: biometrics, critical infrastructure, education, employment, and access to essential private and public services. Emergency call triage and dispatch prioritisation, clinical patient triage, candidate screening and evaluation, creditworthiness assessment, life and health insurance pricing, benefit eligibility decisions and exam proctoring all fall inside it. Appointment booking, claim capture, billing, order status and outbound campaigns generally do not. The Act does not care that a conversation happened; it cares whether an automated system influenced a consequential decision about a person.
Annex III point 1(a) makes remote biometric identification high-risk but carves out biometric verification whose sole purpose is confirming a person is who they claim to be. A voiceprint check against the account a caller has already identified is one-to-one verification and sits outside the list. Searching a caller's voice against a database of enrolled voices is one-to-many identification, and is high-risk. The two look nearly identical in a demo and differ by an entire conformity assessment.
Chapter III turns a product into a regulated product: a lifecycle risk management system, data governance covering accent and dialect representativeness, Annex IV technical documentation, instructions for use, declared accuracy that holds in production, quality management, conformity assessment, CE marking and EU database registration. Once live: Article 12 logging deep enough to trace how an outcome was produced, designed-in human oversight under Article 14, post-market monitoring, and serious incident reporting within 15 days: 10 where a death is involved, 2 for widespread infringement.
Deployers owe a shorter list under Articles 26 and 27: operate per instructions, competent human oversight, six months of log retention, worker notification, and a fundamental rights impact assessment for public bodies and for credit and life and health insurance pricing. But Article 25 turns a deployer into a full provider if it puts its own brand on a high-risk system, substantially modifies it, or changes the intended purpose so that it becomes high-risk. White-labelling the agent, rewriting the prompt and tools, or repointing a booking agent at triage are all live Article 25 questions.
Article 2 reaches providers placing systems on the EU market wherever they are established, and providers and deployers outside the EU where the system's output is used in the EU. A UK voice AI vendor with an Irish or German customer is a provider under the Act. In practice, the commercial pressure arrives before the legal one: EU-facing procurement teams are already asking for Annex IV documentation.
Read closely, the AI Act is a specification for a voice system an enterprise can defend: documented purpose, governed knowledge, declared accuracy, logged decisions, real human oversight and traceable model versions. Harmonised standards are still being written and the Annex III timetable may yet shift, but a delay buys documentation time, not architectural time. Logging, oversight and traceability are design decisions, and they are far more expensive to retrofit than to build.