Outclarity

The EU AI Act and your business process: what a service firm may actually automate

Most of what a service business wants to do with AI sits in the lowest risk band and needs no conformity assessment. Three things do not, and two of them are the ones firms try first.

Applied AI 21 August 2026Updated 30 August 2026 4 min read

The AI Act is discussed in German service businesses in one of two registers: as a reason to do nothing, or as something that applies to somebody else. Both are wrong in ways that cost money — the first forgoes a genuine operational return, and the second walks a firm into the one category where the obligations are real.

The Act is risk-tiered. What matters for an ordinary service business is knowing which tier a given use lands in, because the difference between the bottom tier and the one above it is the difference between a paragraph of disclosure and a compliance programme.

The tiers, in the terms a business actually needs

  • Prohibited. Social scoring, emotion inference in the workplace, certain biometric categorisation. Not a grey area, and not something a service firm stumbles into by accident — with one exception noted below.
  • High-risk. Employment and worker management, creditworthiness assessment, access to essential services, education access, and several others. Real obligations: risk management, data governance, documentation, logging, human oversight, accuracy and robustness.
  • Limited risk — transparency. Systems that interact with people, or generate content. The duty is to say so: a person must know they are dealing with a machine, and synthetic content must be marked.
  • Minimal risk. Almost everything else, including nearly every internal productivity use. No specific obligations beyond the general ones you already have.

Where the ordinary uses land

The three processes most worth automating in a service business — reading customer text at volume, drafting for human approval, and writing the internal summary nobody has time for — are minimal risk. None of them assesses a person, decides access to anything, or operates without review.

A customer-facing chatbot moves up one tier, into transparency: the customer must be able to tell it is not a person. That is a sentence in the interface, not a programme.

The three that are not minimal risk — and two of them are what firms try first

1. Anything in recruitment

CV screening, ranking applicants, sifting, scoring a video interview. This is squarely high-risk, and it is consistently the first thing a growing firm wants to automate because the pain is obvious and the volume is high. The obligations that follow are substantial, and they attach to the deployer as well as the provider.

2. Anything in worker management

Allocating tasks, monitoring performance, informing promotion or termination. Also high-risk. And note that inferring an employee's emotional state at work — from call recordings, from video — is in the prohibited tier rather than merely the regulated one. This is the single way an ordinary service business walks into the top category by accident, usually via a call-centre analytics product bought for quality assurance.

3. Creditworthiness and access decisions

Deciding whether to extend terms, offer a payment plan, or accept a customer on the basis of an automated assessment. High-risk, and additionally caught by Article 22 of the GDPR if it is solely automated and significant.

The uses that are easiest to justify to a board are the ones the Act regulates hardest. The ones that pay for themselves quietly are the ones it barely touches.

Why the compliance question and the value question point the same way

The German layer on top

Two things sit above the Act for a German firm and are frequently the binding constraint in practice.

  • The works council. Where one exists, introducing a system capable of monitoring performance or behaviour engages co-determination under §87 BetrVG. In practice this is decided before the AI Act ever comes up, and a pilot launched without that conversation is a pilot that gets stopped.
  • Data protection. Customer reviews naming individuals are personal data. Lawful basis, the processing record, and the arrangements for any transfer outside the EEA all apply exactly as they always did — the AI Act sits beside the GDPR, it does not replace any part of it.

A defensible starting position

  1. Keep the first project in the minimal-risk band: reading, drafting for approval, summarising.
  2. Keep a named person accountable for every output that leaves the building.
  3. Write one page recording what the system does, what data it sees, and who reviews it. This is not yet a legal requirement at minimal risk — it is what makes the next conversation, with a works council or an enterprise client, short.
  4. Compute every number in code rather than asking a model for it. This is a quality rule rather than a legal one, and it is the rule that decides whether the output survives being questioned.
  5. Stay out of recruitment, worker monitoring and credit decisions until the rest is running and somebody owns the compliance work.

This is an operational summary written for people choosing a first project, not legal advice. Where a use sits near the high-risk boundary, that is the point to involve counsel — and the boundary is closer than most firms assume.

What to take away

  • Reading, drafting-for-approval and summarising are minimal risk. A customer-facing bot is transparency-tier: say it is a machine.
  • Recruitment and worker management are high-risk, and emotion inference at work is prohibited outright.
  • Credit and access decisions are high-risk and also engage GDPR Article 22.
  • In Germany the works council conversation usually binds before the AI Act does.
  • Start in the minimal-risk band, keep a person accountable, and write the one-page description now rather than later.