Voice Bot Control: Operating Voicebots in the Contact Center in a Legally Compliant Manner (EU AI Act + GDPR)
Operating voicebots in a legally compliant manner: Duty to disclose (EU AI Act Art. 50), consent & recording (Section 201 of the German Criminal Code - StGB, GDPR), ban on emotion recognition, and AI quality assurance.
Why Voicebots Need Their Own Compliance Rules
Voicebots — AI systems that speak independently with callers on the phone — have long been part of everyday life in contact centers. As soon as they conduct, record, and evaluate calls, several sets of rules interlock: the transparency and risk rules of the EU AI Act, the data protection requirements of the GDPR, and the criminally protected spoken word. Anyone operating voicebots therefore needs a clear control framework — this is exactly what "Voice Bot Control" means: the verifiable, compliant operation of AI telephony.
Labeling Obligation: Callers Must Know They Are Speaking with an AI
The central requirement of the EU AI Act for voicebots is the transparency obligation according to Art. 50: Natural persons must be informed that they are interacting with an AI system — unless this is obvious. These transparency obligations have applied since August 2, 2026. In practice, this means: a clear announcement at the start of the conversation that an AI voice assistant is speaking, and typically the option to transfer to a human employee.
Recording and Consent: GDPR and § 201 StGB Also Apply to Bots
If the voicebot records or transcribes calls, it processes personal data — the same legal basis applies here as for any call recording. For callers, this is generally consent (Art. 6 para. 1 lit. a GDPR), namely as an active opt-in, not as a mere opt-out notice. In addition, § 201 of the German Criminal Code (StGB) criminally protects the non-publicly spoken word. For clean operation, the voicebot therefore needs three components: labeling as AI, comprehensible information about the recording and purpose, and active consent — with a reference to further details in the privacy policy.
Emotion Recognition in the Workplace Is Prohibited
A strict ban in the EU AI Act concerns evaluation: emotion recognition in the workplace with respect to one's own employees is generally prohibited (Art. 5), with narrow exceptions. Therefore, AI-supported quality assurance of voicebot and agent calls must not aim to evaluate the emotions of employees, but rather the content, structure, and compliance of the calls. Systems that evaluate call content or behavior can also be classified as high-risk and are then subject to stricter obligations.
Data Processing in the EU and Storage Limitation
The GDPR requires control over where data is processed — not just where it is stored. Voicebot solutions that route audio for transcription to servers outside the EU create compliance gaps. EU hosting, data processing agreements, and configurable, sparse storage are therefore recommended — down to "transcript excerpts only instead of full recording", combined with automatically enforced retention periods and purpose limitation.
Quality Assurance: Monitoring and Improving Voicebot Calls
Voice Bot Control also means systematically checking bot conversations: Does the bot fulfill the mandatory announcements? Does it recognize when it needs to hand over to a human? Are the answers correct and compliant? AI-supported quality assurance fully evaluates conversations — objectively, consistently, and traceably — and makes weaknesses and compliance risks visible early on, without the prohibited emotional evaluation of employees.
Implementation in Practice
For legally compliant voicebot operation, a clear process is recommended: First, set up the AI labeling and the comprehensible recording notice with active opt-in, and enable transfer to a human. Next, ensure data processing within the EU, store recordings in an encrypted and audit-proof manner, automatically enforce retention periods, and strictly limit access. After that, check the voicebot calls using AI quality assurance for content and compliance — not for employee emotions — and document everything seamlessly.
How onsoft Supports This
With Voice Bot Control, onsoft bundles legally compliant recording, audit-proof storage, and AI quality assurance for AI telephony into a single system. This allows labeling, consent, and recording to be cleanly mapped, voicebot calls to be fully and compliantly evaluated, and the entire operation to be traceably documented — keeping EU AI Act transparency, GDPR verification, and service quality within one framework.
Frequently Asked Questions (FAQ)
Does a voicebot have to state that it is an AI?
Yes. According to Art. 50 of the EU AI Act, individuals must be informed that they are speaking with an AI system, unless this is obvious. This transparency obligation has applied since August 2, 2026; a clear announcement and the option to transfer to a human are standard practice.
Does recording voicebot conversations require consent?
Yes. If the bot records or transcribes, the GDPR (typically consent under Art. 6 para. 1 lit. a as an active opt-in) and § 201 StGB apply. Without valid consent, the recording is unlawful.
Can a voicebot evaluate the emotions of employees?
No. Emotion recognition in the workplace with respect to employees is fundamentally prohibited under Art. 5 of the EU AI Act. Quality assurance should focus on content, structure, and compliance, not on emotions.
Where can the voice data be processed?
The GDPR requires control over the processing location. If the voicebot routes audio for transcription outside the EU, compliance gaps arise; EU hosting, data processing agreements, and sparse, time-limited storage are recommended.
What does "Voice Bot Control" mean?
The demonstrably compliant operation of AI telephony: labeling as AI, consent and legally secure recording, EU data processing, and AI quality assurance of bot conversations — documented in a single system.


