The EU AI Act: what it means if you use a virtual assistant

The European artificial intelligence law enters general application in August 2026. In plain language, what it means for an appointment-based business.

Europe has been the first to put rules on artificial intelligence. Regulation (EU) 2024/1689 — the so-called AI Act — entered into force in August 2024 and its general application arrives on 2 August 2026. If your business uses a virtual assistant to look after your clients, it is worth knowing what it says, even if most of the weight does not fall on you.

This article is general guidance, not legal advice. The timeline and the detail may be updated: for your specific case, check official sources and consult a professional.

The underlying idea: not all AI is the same

The regulation does not regulate “AI” as a block, but by risk level. That is the key to understanding everything else:

  • Unacceptable risk. Practices that are outright prohibited: manipulating people in ways that cause them harm, exploiting vulnerabilities, social scoring or emotion recognition at work, among others. They have been prohibited since February 2025.
  • High risk. Systems that can seriously affect people's rights or safety: recruitment, access to essential services, certain healthcare uses… They carry strong obligations on documentation, human oversight and data quality.
  • Limited risk. This is where most conversational assistants sit. The core obligation is transparency: the person must know they are talking to an AI.
  • Minimal risk. Everything else, with no specific obligations.

An assistant that replies to messages, explains opening hours and books appointments generally sits in that limited risk territory: it does not decide anyone's access to an essential service and does not evaluate people. It is a service and scheduling tool.

The timeline, in short

Application comes in phases:

  1. February 2025 — the prohibited practices take effect, along with the AI literacy obligation: whoever uses these systems must have enough training to understand them.
  2. August 2025 — obligations for general-purpose AI models and most of the penalty regime.
  3. August 2026general application, including the transparency obligation that affects conversational assistants.
  4. August 2027 — the final phase, for AI embedded in products already regulated elsewhere.

What falls to you as a business

Here is the good news. The regulation distinguishes between whoever develops the system (the provider) and whoever uses it in their activity (the deployer). If you buy a virtual assistant, you are the latter, and the bulk of the technical obligations — documentation, assessment, quality — falls on whoever builds it.

What does fall to you is fairly reasonable: use the system as intended, make sure your team understands what the tool does, and do not put it to uses it was not designed for. We go into it in whose responsibility is it.

Where ClaudIA sits in all this

ClaudIA is a service and scheduling virtual assistant: it replies, informs and books. It does not evaluate people, does not decide access to any essential service and does not make clinical decisions. When a conversation goes beyond what it can resolve, it passes it to someone on the team.

On top of that come decisions that were already taken before the law tightened: data is processed and stored in the European Union, conversations are logged and the business can pause the assistant whenever it wants. You can see everything ClaudIA does and how it fits your sector.

The AI Act is not a threat to anyone using these tools sensibly. It is, above all, a way of separating those who build with judgement from those who improvise.

Keep reading