AI answers, virtual agents, auto-triage, reply drafting — the AI features in your service desk are on, and someone just asked what the EU AI Act requires. Here is the obligation-by-obligation answer for support and IT ops teams: what applies now, what applies from 2 August 2026, and the edge cases that escalate.
A customer-support AI chatbot is not high-risk by default — customer support is not one of the Annex III areas. But that is not the same as “nothing applies”: the Article 50 transparency duties apply from 2 August 2026, the Article 4 AI literacy duty and the Article 5 prohibitions already apply — and an internal HR or education helpdesk can tip the same technology into high-risk territory.
In the space of about two years, AI in the service desk went from demo to default. Jira Service Management ships a virtual service agent on Cloud Premium and Enterprise, whose AI answers use generative AI over your linked knowledge-base spaces and respond to customers in the portal, in Slack and in Teams. Zendesk, Freshservice, Intercom and ServiceNow ship equivalents. Most teams switched these features on the way they switch on any feature — a toggle, a pilot queue, done.
Then the EU AI Act deadlines started making headlines, and the question landed in the support manager’s inbox: do we need to register this? Are we “high-risk” now? The honest answer is more boring and more precise than the headlines — and it depends on which of four AI patterns your service desk actually runs:
None of these appears in Annex III. So the classification question has a clear default answer — and the real work sits in a handful of narrower obligations that apply anyway.
Here is the map for a typical customer-facing service desk that has switched on vendor AI features. Dates reflect the Digital Omnibus on AI (Regulation (EU) 2026/1744), published in the Official Journal on 24 July 2026 and in force since 27 July 2026.
| Obligation | Your service desk? | Since when |
|---|---|---|
| Art 50(1) — disclose the AI interaction People interacting with an AI system must be informed they are talking to AI, unless it is obvious | Applies | 2 August 2026 |
| Art 50(2) — mark synthetic content Outputs of generative AI must be marked as artificially generated in a machine-readable way — a provider-side duty that matters to you mainly if you build your own bot | Provider-side | 2 August 2026; grace until 2 Dec 2026 only for generative AI systems already on the market before 2 Aug 2026 |
| Art 4 — AI literacy Take measures to ensure a sufficient level of AI literacy in staff operating AI — softened to an effort obligation by the Omnibus | Applies | Already in force |
| Art 5 — prohibited practices Relevant limb: emotion recognition in the workplace (Art 5(1)(f)) — see the nuance below | Applies — narrow | Since 2 February 2025; fines up to €35M / 7% of global turnover |
| Art 9 risk management · Art 13 transparency to deployers · Art 26 deployer duties The high-risk stack | Only if high-risk | 2 December 2027 (standalone AI); 2 August 2028 (AI embedded in products under EU safety legislation) |
This is the obligation that bites first and bites almost every service desk. AI systems intended to interact directly with natural persons must be designed so those persons are informed that they are interacting with an AI system — unless this is “obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect” given the context. Do not lean on the “obvious” carve-out: what is obvious to your team is not obvious to a frustrated customer at 23:40. The safe pattern is simple — label the virtual agent as AI at the start of the conversation, in every channel it operates in (portal, Slack, Teams), and make the handover to a human explicit. The full decoder is at Article 50 transparency obligations, and the customer-support specifics are in AI Chatbot Transparency Rules in Customer Support.
The synthetic-content marking duty sits with the provider of the generative system — for a vendor feature, that is your vendor’s engineering problem, and a fair question to put in writing to them. It becomes your problem if you build a bot on a model API yourself. One timing detail worth knowing: the grace period until 2 December 2026 exists only for generative AI systems already placed on the market before 2 August 2026 — anything launched after that date must comply from day one.
Since the Omnibus, Article 4 is an effort obligation: you must take measures to ensure, as far as you can, that agents and admins operating the AI have a sufficient level of AI literacy. For a service desk this is refreshingly concrete — agents should know what the AI answers can and cannot do, when to distrust a drafted reply, and how the escalation path works. A short training block plus a one-page guideline is a defensible start; zero documented effort is not.
One prohibition is genuinely relevant to service desks, and it is widely misread in both directions. Article 5(1)(f) bans AI systems that infer the emotions of a natural person in the areas of workplace and education institutions (except for medical or safety reasons). Read that scope carefully:
Same feature, different subjects, different law. A “sentiment” toggle in a service desk product is not one legal thing. Applied to customers it is a routing signal; applied to employees it can be a prohibited practice. When you record the use case, record whose emotions are being inferred — that single field decides which regime you are in.
“Customer support is not in Annex III” holds only as long as the service desk stays a service desk. Classification under Article 6(2) follows the intended use, not the product category — and two internal patterns walk straight into listed areas:
If one of your use cases lands in Annex III, the high-risk stack attaches: the provider owes a risk management system (Article 9) and transparency to deployers (Article 13); your organisation owes the deployer obligations of Article 26 — human oversight, input-data control, monitoring, log retention. Those obligations bite from 2 December 2027 for standalone AI systems (2 August 2028 for AI embedded in products under EU safety legislation) — deferred from the original 2 August 2026 by the Omnibus. Distant enough to plan for; close enough that “we’ll look at it later” is not a plan.
Almost every service desk team reading this is a deployer: you use an AI system under your own authority, but the technology is the vendor’s. Switching on the Jira Service Management virtual service agent makes Atlassian the provider and your organisation the deployer — the provider carries the build-side obligations (including Art 50(2) marking and, if ever high-risk, Articles 9 and 13), while you carry the use-side ones: disclosure in practice, AI literacy, staying clear of prohibited configurations, and — for high-risk use cases — Article 26.
One caution before anyone gets creative: if you substantially modify the system or repurpose it for a materially different intended use — say, rewiring the support bot into an HR screening tool — provider obligations can shift onto you. The deeper Jira-specific walkthrough is in Does Your Jira Service Management AI Fall Under the EU AI Act?
For a support or IT ops lead, the compliant path is short and mostly organisational:
Model Inventory for Jira turns each AI use case into a work item in the Jira your team already uses, with a built-in EU AI Act category field and dynamic risk tiering. Register the virtual agent, the triage model and the reply drafting as separate entries, record the “not high-risk” verdict with its rationale and who signed it off — with an immutable change history, so when the vendor switches on a new AI capability, the record shows the classification needs a re-check. The legal judgement stays with your compliance team; the inventory makes sure no feature skips the question.
See how it worksNo, not by default — customer support is not an Annex III area, so a support chatbot, virtual agent or triage feature is not high-risk under Article 6(2) as such. Article 50 transparency (from 2 August 2026), Article 4 literacy and the Article 5 prohibitions apply regardless.
Yes, unless it is genuinely obvious to a reasonably well-informed, observant and circumspect person in the circumstances. From 2 August 2026, label the AI in every channel — portal, Slack, Teams — and do not pass AI-drafted replies off as a named human where that would mislead.
Yes. Using the feature under your own authority makes you a deployer: the vendor carries provider duties, you carry disclosure-in-practice, AI literacy and the prohibited-practices screen — and Article 26 if a use case is high-risk. Substantially modifying or repurposing the system can shift provider duties to you.
Not for customer tickets — the Article 5(1)(f) ban covers emotion inference in the workplace (and education institutions). Consumer sentiment triage is outside it; emotion analytics on your own agents or on employees using an internal helpdesk is inside it, and has been prohibited since February 2025.
Only if a use case becomes high-risk — typically an internal HR desk materially influencing employment decisions or an education helpdesk influencing admission or assessment. Those obligations apply from 2 December 2027 (standalone AI) or 2 August 2028 (AI embedded in products under EU safety legislation), per the Digital Omnibus in force since 27 July 2026.
This page is a practical explanation, not legal advice. Always confirm classification against the official text of Regulation (EU) 2024/1689 and, where the stakes warrant it, qualified counsel.