WhatsApp Business News

AI Act 2026: What are the obligations for companies using AI agents?

Written by François Benveniste | Aug 3, 2026, 8:42:51 AM

 

Artificial intelligence is rapidly becoming part of everyday business operations. Customer service, marketing, sales, HR and internal processes are increasingly powered by conversational AI, chatbots and AI assistants.

To support this transformation, the European Union introduced the AI Act, the world's first comprehensive regulation on artificial intelligence.

2 August 2026 marks a major milestone in its implementation. Several key provisions become applicable and enforcement begins across the EU.

For companies deploying AI agents, this is not about slowing down innovation. It is about ensuring AI is used transparently, responsibly and with appropriate governance.

In this article, we explain what the AI Act means for organisations using conversational AI and share the recommendations we provide to Sandra customers.

Not every automation is AI

One of the most important contributions of the AI Act is that it clearly defines what an AI system actually is.

Despite the widespread use of the term "AI", not every automated workflow falls within the scope of the regulation.

According to the AI Act, an AI system is one that can infer outputs from the data it receives—for example by understanding natural language, generating content, making recommendations or supporting decisions with a degree of autonomy. By contrast, software that simply follows predefined rules is generally not considered an AI system.

Examples

These are generally not AI systems:

  • sending an automatic WhatsApp message after a purchase;
  • launching a follow-up campaign after three days;
  • executing a Make, n8n or Zapier workflow based solely on rules;
  • triggering a CRM automation sequence.

These are AI systems:

  • understanding questions written in natural language;
  • automatically qualifying customer requests;
  • rewriting an order or agreement;
  • searching a knowledge base;
  • generating personalised responses;
  • preparing quotes, contracts or other documents from a conversation.

This distinction matters. AI should be used where it genuinely adds intelligence and value. In many situations, traditional automation remains simpler, more reliable and more cost-effective.

 

What does the AI Act mean for Sandra customers?

Most conversational agents built with Sandra rely on AI models and therefore fall within the scope of the AI Act.

For the majority of conversational use cases, four key areas deserve particular attention.

1. Inform users when they are interacting with AI

The AI Act introduces transparency obligations whenever people interact directly with an AI system, unless this is already obvious.

In practice, a simple message at the beginning of the conversation is usually sufficient.

For example:

Hello 👋 I'm the AI assistant for [Company]. I'll help you with your request. You'll always be able to review and confirm the information before it is submitted.

This simple step helps meet regulatory expectations while increasing user trust.

2. Ensure appropriate human oversight

AI agents can qualify leads, prepare quotations, answer customer questions or assist employees.

However, whenever a process involves contractual commitments, sensitive decisions or complex situations, organisations should ensure an appropriate level of human review or intervention.

The objective is to benefit from AI while maintaining control over important business decisions.

3. Document your AI agents

Just as GDPR encouraged organisations to maintain a Record of Processing Activities (RoPA), the AI Act introduces a stronger governance approach for AI systems.

Companies should know:

  • which AI agents are deployed;
  • what their purpose is;
  • which AI models they use;
  • what data they process;
  • which systems they connect to;
  • who is responsible for each agent.

Beyond regulatory compliance, this documentation greatly simplifies governance, maintenance and future audits.

La majorité des agents conversationnels développés avec Sandra utilisent des modèles d'intelligence artificielle et entrent donc dans le périmètre de l'AI Act.

4. Train your teams

The AI Act also introduces an AI Literacy requirement.

Employees using or supervising AI systems should have an appropriate level of understanding of AI capabilities, limitations, risks and best practices.

AI governance is not only about technology—it is also about people.

Sandra's recommendations

For organisations deploying conversational AI, we recommend four practical actions:

  • clearly inform users when they interact with AI;
  • ensure appropriate human oversight where necessary;
  • maintain documentation for all deployed AI agents;
  • train the teams responsible for using and managing these systems.

These measures provide a solid foundation for responsible AI adoption and align with the principles introduced by the AI Act.

Sandra supports your AI journey

Deploying AI successfully goes beyond technology.

Sandra also helps organisations build the right governance framework through dedicated training covering:

  • AI fundamentals and the AI Act;
  • best practices for using AI agents;
  • conversational AI design and administration;
  • AI governance, GDPR and AI Act compliance.

Our objective is to help organisations deploy conversational AI responsibly while remaining prepared for evolving regulatory requirements.

Coming soon: the Sandra AI Control Center

The next challenge for organisations will not be creating AI agents—it will be governing them.

This is why we are currently developing the next evolution of Sandra around an AI Control Center, providing organisations with a centralised view of all AI agents configured within the platform, together with their documentation and governance information.

Our long-term vision is to combine AI governance with GDPR principles, creating a unified register of AI agents and data processing activities generated directly from Sandra's configuration.

Conclusion

The AI Act represents an important step in the maturity of artificial intelligence across Europe.

Rather than limiting innovation, it provides a framework for building AI systems that are more transparent, better governed and more trustworthy.

At Sandra, we believe organisations that adopt these best practices today will not only strengthen their regulatory readiness, but also increase the confidence of their customers, employees and partners.

 

Further reading

Pour les lecteurs souhaitant consulter les textes et ressources officielles :