RatedWithAI

RatedWithAI

Accessibility scanner

AI RegulationJuly 24, 2026

EU AI Act for Telecom Companies 2026: Network AI, Fraud & Customer Compliance

Carriers run more AI than almost any other industry — network tuning, fraud scoring, churn prediction, chatbots, identity verification — and most of it is unregulated by the EU AI Act. The exposure isn't in the volume of AI, it's in two specific corners: emotion-recognition in customer service, and biometric identity checks at SIM registration.

Prohibited
Emotion-recognition AI in call-center/agent workflows
Aug 2026
Enforcement deadline for high-risk telecom AI systems
€35M
Max fine for prohibited-practice violations (or 7% global turnover)

Most Telecom AI Isn't High-Risk — But Two Use Cases Are Landmines

Telecom is unusual under the EU AI Act because the industry's biggest AI workloads — network self-optimization, capacity forecasting, predictive maintenance on cell sites, churn-prediction models, and general customer-support chatbots — sit outside Annex III entirely. None of that is named as high-risk, and general-purpose chatbots only trigger light transparency obligations (disclose that the user is talking to AI).

The risk concentrates in two places carriers don't always flag as "AI compliance" problems: emotion-recognition systems used on call-center staff or customers, and biometric identity verification used to fight SIM-swap fraud and enforce eSIM know-your-customer rules.

Where Telecom AI Sits on the Risk Ladder

Prohibited or High-Risk
  • Emotion-recognition in call centers or workforce monitoring
  • Biometric identification for SIM/eSIM registration (1:many match)
  • AI-driven credit checks tied to postpaid plan approval
  • Real-time biometric surveillance features in carrier-branded apps
Usually Minimal Obligation
  • Network optimization and RAN tuning
  • Predictive maintenance on infrastructure
  • Fraud/anomaly detection on billing and usage
  • Churn prediction and retention offers
  • General customer-support chatbots (transparency only)
  • Spam/robocall filtering

The Emotion-Recognition Trap in Call Centers

A number of contact-center vendors sell "sentiment analytics" or "agent coaching AI" that infers caller or agent emotional state from voice tone in real time. Under the EU AI Act, emotion-recognition systems are flatly prohibited in workplace and education settings — this has applied since February 2025, well ahead of the August 2026 high-risk deadline. A carrier using this kind of tool to score agent performance, flag "distressed" callers for escalation, or gate bonuses on inferred emotional tone is running a prohibited practice, not a high-risk one requiring documentation — there's no compliance path, only removal.

Voice-based fraud detection (verifying a caller is who they claim to be) is a different category and generally not caught by this prohibition — the line is whether the system is inferring emotions versus verifying identity or detecting anomalies.

Biometric Identity Checks at Registration

SIM-swap fraud has pushed carriers toward biometric verification at point of sale and in self-service apps — matching a selfie against an ID document, or against a database of prior registrations to catch repeat fraud. One-to-one verification (does this selfie match this ID) is treated more leniently than one-to-many identification (does this face match anyone in our fraud database). The latter is where high-risk obligations attach: documented accuracy testing, human oversight on denials, and a way for a legitimate customer wrongly flagged to get a human review.

Compliance Checklist for Carriers

Immediate Actions

  • Audit call-center vendor contracts for emotion/sentiment AI features
  • Disable or remove any emotion-inference tooling used on staff or callers
  • Classify SIM/eSIM biometric checks as 1:1 verification or 1:many identification
  • Confirm chatbots disclose AI use to customers

Before August 2026

  • Build technical documentation for any 1:many biometric identification system
  • Add human review path for biometric-flagged registration denials
  • Run bias testing on postpaid credit-approval AI if used
  • Designate an AI Act compliance owner across network, fraud, and CX teams

Frequently Asked Questions

We use AI to detect SIM-swap fraud in real time. Is that prohibited?

No — fraud detection and anomaly scoring are not emotion-recognition and are not on the prohibited list. The prohibition targets systems that infer a person's emotional state, not systems that flag suspicious account activity.

Our chatbot uses a general-purpose foundation model. Does that add obligations?

If you're deploying a third-party GPAI model, most obligations sit with the model provider, not you as a deployer — but you still must disclose to users that they're interacting with AI, which is a Article 50 transparency requirement that applies regardless of risk tier.

Does network self-optimization AI ever become high-risk?

Only if it starts making decisions with a direct impact on named high-risk categories — for example, if a network-management AI also gates access to emergency services in a way that affects individuals. Pure RAN tuning and capacity planning stays outside Annex III.

We're a US carrier with an EU roaming agreement only. Are we in scope?

Scope turns on whether your AI system's output is used within the EU or affects people located there. Roaming partnerships alone don't automatically trigger this, but if your fraud or verification AI processes data on EU-based subscribers directly, you may fall in scope for that system.

The Fix Is Narrower Than It Looks

Most of a carrier's AI stack — network ops, churn, billing fraud — needs no new compliance program. The real work is a targeted audit of call-center vendor tooling for emotion-recognition features and a clear-eyed classification of biometric identity checks at registration.

Get those two areas documented and remediated, and telecom AI compliance is largely a paperwork exercise, not a product overhaul.