Summarize Content With:
The Digital Omnibus Is Law: What Actually Changes for AI Phone Agents in 2026
The short answer for anyone running or launching an AI phone agent: your disclosure duty was not delayed. Article 50 of the EU AI Act has applied since 2 August 2026. If a machine answers your calls today, the caller must be told β clearly enough that a reasonably attentive person understands it. What was delayed are the obligations for high-risk systems under Annex III, and those moved to 2 December 2027.
The confusion comes from the Digital Omnibus on AI β Regulation (EU) 2026/1744. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Since then, plenty of coverage has been summarised as "the AI Act is delayed." That framing is wrong in general and actively risky for voice operators, because the one article that touches phone agents most directly stayed exactly where it was. This guide sorts out the timeline, translates Article 50 into concrete greetings, and shows what a clinic, law firm, or support line should fix this week.
What the Digital Omnibus is β and what it is not
The Digital Omnibus on AI is not a new law. It is an amending regulation that reaches into the existing AI Act with three stated goals: simplify EU digital rules, ease the burden on smaller providers, and buy time for the most technically demanding obligations. The Commission proposed the package in November 2025; the final text has been on the books since late July 2026.
What the Omnibus does not do: it leaves both the prohibition regime in Article 5 and the transparency duties in Article 50 intact. If anything it tightens things β it adds two further prohibited practices that bite from 2 December 2026. Skimming the headlines and concluding that "nothing happens in 2026" leads to a bad decision.
The revised timeline at a glance
The table below summarises what Regulation (EU) 2026/1744 moved and what it left alone. It is the basis for any realistic compliance plan in the voice space.
| Obligation | Originally | After Digital Omnibus | Relevance for phone agents |
|---|---|---|---|
| Prohibited practices (Art. 5) | 2 February 2025 | unchanged | High β e.g. emotion recognition at work |
| Transparency (Art. 50) | 2 August 2026 | unchanged | Very high β applies to every voice agent |
| Marking of AI content (Art. 50(2)), systems on market before 2 Aug 2026 | 2 August 2026 | 2 December 2026 | Medium β narrow grace period for legacy systems |
| Two new prohibitions (Art. 5) | β | 2 December 2026 | Low for voice, relevant for governance |
| High-risk under Annex III | 2 August 2026 | 2 December 2027 | Depends on use case β see below |
| High-risk under Annex I (embedded) | 2 August 2027 | 2 August 2028 | Low for pure telephony |
The one-liner for your leadership team: transparency now, high-risk later. The extra sixteen months apply to conformity assessment, risk management systems, and technical documentation for Annex III applications β not to whether your caller has to learn they are talking to a machine.
Article 50 on the phone: what exactly must be said
Article 50(1) requires providers of AI systems intended to interact directly with natural persons to design those systems so the person is informed that they are interacting with an AI system β unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person.
In practice that means: with a voice agent speaking in a natural voice, it is precisely not obvious. Modern text-to-speech is engineered to sound human β that is the product promise. Which is exactly why the exemption rarely applies here. The disclosure belongs at the start of the call, not in your website footer and not four minutes in.
We covered the exact wording options in depth in our guide to Article 50 and what your AI phone agent must say. This piece is about what the Omnibus changed there β which is nothing. Three requirements have emerged in practice:
- Early: in the first sentence, before the caller explains why they are calling.
- Clear: no marketing language, no terms that obscure the AI nature of the system.
- Perceivable: at normal speaking pace, not rattled off like fine print.
| Assessment | Example greeting | Why |
|---|---|---|
| Defensible | "Hello, this is the digital assistant at Becker Dental. I'm an AI and I can book appointments or put you through to the team. How can I help?" | AI nature explicit, first sentence, escalation path included |
| Defensible | "Welcome to Hotel Lakeview. You're speaking with our AI assistant for reservations." | Short, unambiguous, contextual |
| Risky | "Hi, my name is Lisa from the service team." | Implies a real employee β no disclosure at all |
| Risky | "You're being assisted by our intelligent system." | "Intelligent system" is not a disclosure in the sense of the article |
| Risky | Notice given only after collecting name, date of birth and request | Too late β the interaction started long ago |
Operationally, you set this greeting once, centrally, and enforce it across every number. In Famulor you maintain the opening line in the prompt editor and then verify in post-call analysis that it actually fired on every single call. That second step is routinely skipped β and it is the part that constitutes your evidence.
What was not delayed β four common misreadings
Misreading 1: "We have until December 2027." That applies only to Annex III high-risk systems. An appointment-booking agent in a clinic typically is not one β its transparency duty has applied since 2 August 2026.
Misreading 2: "The December 2026 date pushes back our greeting." It does not. 2 December 2026 concerns only Article 50(2) β machine-readable marking of AI-generated content β and only for systems placed on the market before 2 August 2026. The direct-interaction disclosure under paragraph 1 has no grace period.
Misreading 3: "We're only a deployer, not a provider." The AI Act addresses providers and deployers separately, but it addresses both. If you run a voice agent under your own name for your customers, obligations attach to you regardless of who built the technology. Agencies and IT service providers reselling white-label agents should nail down the role split contractually.
Misreading 4: "This is an enterprise problem." The penalty provisions have no headcount threshold. For SMEs the only concession is that the lower of the two amounts applies β a cap, not an exemption.
Is an AI phone assistant a high-risk system?
In the large majority of cases: no. An agent that books appointments, answers opening-hours questions, takes callback requests, or reads out order status is a transparency case, not a high-risk case. It becomes high-risk only when the application reaches into one of the Annex III areas. Four constellations matter for telephony:
- Employment: screening or evaluating candidates in a recruitment process.
- Creditworthiness: assessing the credit standing of natural persons during the call.
- Essential private and public services: for example triage decisions affecting access to emergency or social services.
- Emotion recognition: here the Article 5 prohibition additionally applies in workplace and education contexts.
A recruitment agent that pre-qualifies candidates by phone and produces a ranking is therefore a different animal from an AI phone assistant in healthcare that only coordinates appointments. Operators in the first category should spend the extra runway to December 2027 rather than let it lapse: risk management, data quality, logging and human oversight cannot be retrofitted in four weeks.
New: the "small mid-cap" category
One of the most practically relevant changes in the Omnibus is a new size class. Until now, relief was reserved for SMEs. The Omnibus adds "small mid-cap" enterprises β companies that no longer qualify as SMEs but employ fewer than 750 people and have either an annual turnover of at most β¬150 million or a balance sheet total of at most β¬129 million.
| Relief measure | Previously | After the Omnibus |
|---|---|---|
| Simplified technical documentation (Annex IV) | SMEs only | SMEs + small mid-caps |
| More proportionate quality-management expectations | SMEs only | SMEs + small mid-caps |
| Priority access to regulatory sandboxes | SMEs only | SMEs + small mid-caps |
| Tailored penalty caps | SMEs only | SMEs + small mid-caps |
For the typical Famulor customer β a clinic group with 40 sites, a trades business with 120 staff, a mid-sized e-commerce operation β this means you almost always land in a relieved class. It does not release you from Article 50, but it materially lowers the documentation burden if your use case ever does tip into high-risk territory.
GDPR keeps running independently
The AI Act replaces nothing in data protection law. A phone call with an AI agent almost always processes personal data β name, phone number, the request itself, and in healthcare contexts potentially Article 9 special-category data. You still need:
- a lawful basis for the processing and, where you record, for the recording itself,
- a data processing agreement with your platform provider,
- an entry in your record of processing activities,
- retention limits for transcripts and recordings,
- a workable way to answer data subject requests.
In practice, the AI Act notice and the data protection notice fit into one sentence without making the call feel heavy: "I'm the AI assistant at Weber Legal. This call is logged so we can handle your request." Details belong in your privacy policy, not the greeting. If you record audio rather than just store transcripts, several EU jurisdictions impose additional requirements on recording spoken conversations; treat that as its own workstream and do not fold it into the AI disclosure.
Penalties: what is at stake
Sanctions follow Article 99 of the AI Act and are tiered. Breaches of the Article 50 transparency duties sit in the middle tier.
| Breach | Cap | Share of annual turnover |
|---|---|---|
| Prohibited practices (Art. 5) | β¬35 million | 7% |
| Transparency duties (Art. 50) and most other obligations | β¬15 million | 3% |
| Incorrect or incomplete information to authorities | β¬7.5 million | 1% |
For companies the higher amount applies; for SMEs and start-ups, the lower one. Enforcement sits with national market surveillance authorities. Realistically, though, a fine is not the first risk a mid-sized operator faces β complaints from data subjects, competitor challenges, and reputational damage arrive faster than a formal proceeding.
Compliance cost: build it yourself or use a platform
The disclosure itself is one sentence. The effort sits in the evidence: six months from now, can you demonstrate the greeting fired on every call? This is where in-house builds and platforms diverge.
| Task | In-house on raw APIs | Platform such as Famulor |
|---|---|---|
| Version the greeting centrally | needs your own prompt management | in the prompt editor, per agent |
| Per-call evidence | your own logging and analysis | call history and post-call analysis |
| Retention limits | implement yourself | platform configuration |
| Data processing agreement | one per sub-processor | one agreement with the provider |
| Provider/deployer role split | entirely on you | contractually pre-structured |
Once you price in the evidence layer, in-house builds routinely come out well above the expected total cost. To sanity-check how that maps to your current call volume:
Estimate your ROI from automating calls
See how much your business could save by switching to AI-powered voice agents.
ROI Result
ROI 228%
No credit card required
Implementation in seven steps
- Build an inventory. List every number, agent, and chat channel where AI speaks to humans β including test numbers that are accidentally reachable.
- Determine your role. Are you a deployer, a provider, or both? For resellers this is the single most important question.
- Write the greeting. One sentence, AI named explicitly, company name, escalation path to a human.
- Roll it out. Apply it to every agent, including rarely used outbound campaigns.
- Sample your calls. Listen to twenty real calls from this week or read the transcripts. Did the greeting fire every time?
- Document it. A short memo: which system, which role, which greeting, since when, who owns it, where the evidence lives.
- Set reminders. Two dates: 2 December 2026 for the new prohibitions and the marking duty for legacy systems, 2 December 2027 for Annex III.
Three industry examples
Becker Dental, 14 staff, two locations. The agent answers calls between noon and 2pm and in the evenings, books check-ups, and escalates pain cases immediately. Not a high-risk case. To do: greeting with AI disclosure and a transfer option, review the data processing agreement, set transcript retention to 90 days. Effort: half a day.
KrΓΌger Plumbing, 38 staff. The agent qualifies emergency callouts and creates jobs. Not a high-risk case. To do: apply the greeting to the emergency extension as well β the classic blind spot, because that number was configured separately.
A staffing firm with 220 employees. The agent calls candidates, runs a structured short interview, and produces a shortlist. That can fall into the Annex III employment area. To do: greeting immediately, and in parallel build risk management, logging, and human final decision-making by December 2027. As a small mid-cap the company can use the simplified technical documentation. For structuring and governing cases like this, the enterprise track is the right entry point.
Common mistakes
- Greeting only on the main number. Secondary numbers, outbound campaigns, and the web widget get forgotten.
- Greeting in the prompt but never verified. A model can skip the opening if the caller speaks immediately. Without sampling you will never notice.
- Obscuring personas. A human first name with no AI disclosure is exactly the situation Article 50 targets.
- Conflating GDPR and the AI Act. You need both, but they are separate records resting on separate legal bases.
- Reading the delay as a free pass. Let sixteen months lapse and you face the same project in late 2027, only with more legacy baggage.
Conclusion
The Digital Omnibus bought breathing room where it was technically needed β conformity assessment and documentation for high-risk systems. For an ordinary AI phone assistant in a clinic, law firm, hotel, or trades business it changes very little: the disclosure duty has applied since 2 August 2026, and meeting it is genuinely manageable. A well-written first sentence, evidence pulled from call analysis, and a two-page memo cover the core.
Your concrete next step: pull twenty calls from this week and check whether your AI identified itself as AI in every one of them. If the greeting is missing on even one channel, fix it today rather than in December. And if you are setting the agent up right now anyway, configure the greeting, the transfer path, and the logging in a single pass.
Try our AI Assistant
Experience how natural our AI phone assistant sounds.
Enter your details and receive a call from our AI agent within seconds.
Agent is trained to discuss Famulor services and book appointments.

Demo AI agent
Famulor representative
FAQ
Was the EU AI Act delayed by the Digital Omnibus?
Only partly. High-risk obligations under Annex III moved to 2 December 2027 and those under Annex I to 2 August 2028. The Article 50 transparency duties have applied unchanged since 2 August 2026.
Does my AI phone agent have to say it is an AI?
Yes, in nearly all cases. Article 50 requires users to be informed they are interacting with an AI system unless that is obvious. With natural-sounding voices, it is not obvious.
When exactly does the disclosure have to happen?
At the start of the interaction, before the caller explains their request. A notice mid-call, or only in the privacy policy, is not sufficient.
What does the 2 December 2026 deadline cover?
Two things: the new Article 5 prohibitions, and the marking duty for AI-generated content under Article 50(2) for systems on the market before 2 August 2026. Direct-interaction disclosure has no grace period.
Is an appointment-booking agent a high-risk system?
Normally not. High-risk status attaches to Annex III applications such as candidate screening, creditworthiness assessment, or access to essential services.
What penalties apply for missing disclosure?
Article 50 breaches fall into the tier of up to β¬15 million or 3% of worldwide annual turnover. For SMEs and start-ups the lower of the two amounts applies.
What is a small mid-cap?
A company that is no longer an SME but has fewer than 750 employees and either up to β¬150 million turnover or up to β¬129 million balance sheet total. These firms now receive the same relief measures as SMEs.
Does the AI Act replace the GDPR?
No. Both apply in parallel. You still need a lawful basis, a data processing agreement, retention limits, and the ability to respond to data subject requests.
Does this apply to outbound calls too?
Yes. The duty attaches to direct interaction, not to call direction. Outbound campaigns are the most commonly overlooked channel in practice.
How do I evidence compliance?
Through your call records. Sample calls regularly to confirm the greeting actually fired, and keep a short written note of the result.
Related blog posts

Connect Microsoft Teams Phone to an AI Voice Agent

Is Your AI Phone Agent Accessible? The 2026 EAA Guide


