New AI rules since August: What phone assistants must comply with now

Published on September 3, 2026

New AI rules since August: What phone assistants must comply with now

An AI phone assistant is quick to set up. A few settings, a phone number, and the machine answers calls. That very ease is why many businesses never ask themselves the crucial question: am I actually allowed to just do this?

On this question, there’s a conversation I highly recommend. Leonard Schmedding interviewed the Cologne-based IT-law attorney Dr. Lutz Keppeler on his Everlast AI channel — the video is titled “Forget the ‘AI Officer’! Is an AI-caller cease-and-desist wave starting?”. Keppeler captures the core problem in one sentence that sticks:

“You’re always operating in gray areas, and that feels perfectly fine for everyone involved — as long as nothing happens at all.” (14:05)

The conversation is from early 2025. And that’s exactly why it’s worth revisiting today: several things that were still in the future back then are now binding law. In several places, the gray area is gone.

In this post, I go through the interview’s key statements, check them against where things stand today — and close with my own conclusion, which turns out differently than the video’s title might suggest.

Three developments have concretely changed the picture since the conversation.

First: the AI labeling obligation is in force. In the interview, the transparency homework from the EU AI Act was still something to be done “at the right time.” That time has come: since August 2, 2026, it must be recognizable that an AI is speaking on the other end. For a phone assistant, that means half a sentence in the greeting. I’ve written up in detail what exactly is required and who the obligation applies to: Labeling AI: What applies to your business since August 2.

Second: the AI supervisory authority exists. In early 2025, Keppeler could still reassure listeners that the competent authority was “not even defined yet” — his bet was on the Bundesnetzagentur, Germany’s Federal Network Agency. That’s exactly how it played out. Since late July 2026, Germany’s implementing act for the EU AI Act has been in force, and the Federal Network Agency is the central AI oversight body in Germany. There is now an authority in charge.

Third: Germany’s Federal Court of Justice has made claiming damages easier. More on that in a moment — for the cease-and-desist topic, this ruling is the most important of all.

For perspective, there’s also an all-clear: the burdensome obligations for high-risk AI were postponed in May 2026 to the end of 2027. And an ordinary phone assistant that books appointments and answers questions isn’t a high-risk system anyway. Anyone telling you otherwise is probably trying to sell you something.

The heart of the interview revolves around one question: what actually happens if someone deploys a phone assistant that isn’t set up properly — can anything really come of it?

The honest answer: yes. The lever is Article 82 of the GDPR (the EU’s data-protection law). It gives affected individuals a claim to damages, even without financial harm. Keppeler calls it one of the most frequently litigated articles in the entire regulation — and case law has since paved that road further. In November 2024, in the Facebook data-leak cases, the BGH (Germany’s Federal Court of Justice) ruled: the mere loss of control over one’s own data is itself a harm. Affected individuals don’t have to prove misuse or demonstrate emotional distress. The typical amount per case is around €100.

€100 sounds harmless. What makes the sum interesting is scale. Since October 2023, Germany has had a collective redress action: consumer associations can use it to claim damages for many affected people at once, explicitly including data-protection violations. In the Facebook data-leak case, plaintiffs were actively rounded up — with ad banners and dedicated sign-up pages. That’s not a future scenario; it’s documented practice.

The interview raises a thought that applies specifically to phone assistants: someone sending legal warnings could themselves use an AI that calls phone assistants en masse and documents violations. After all, anyone can test a public phone number. Whether that ever becomes a business model is open — but technically, little stands in the way.

There is, however, the other side too, and Keppeler tells it with palpable delight: the Google Fonts warning-letter scheme. After a Munich ruling in early 2022 that awarded a website visitor €100, a duo mass-mailed demand letters to website operators. The scheme fell apart because an automated program had visited the websites — sometimes seconds apart. No court believed anymore that anyone had felt personally harmed. Sloppy warning-letter senders lose.

What does that mean for you as a business owner? The risk is real, but it’s manageable. It mostly hits those who did nothing at all: no updated privacy policy, no AI disclosure, no contract with the provider. Exactly these basics are the difference between an expensive letter and a brief annoyance.

A German AI provider doesn’t automatically mean GDPR-compliant

One shortcut many businesses have in mind gets thoroughly dismantled in the interview: just pick a German provider, and the data-protection issue is handled.

“If someone delivers the frontend in Germany but uses all the tools from the US, then at first I’ve really gained nothing in terms of compliance guarantees.” (7:51)

The background: the powerful AI language models inside phone assistants almost always run on US cloud infrastructure. A German company sign out front doesn’t change that. A purely German or European stack that can keep up with the big systems still doesn’t exist.

That doesn’t make data transfers to the US illegal — there’s an agreement between the EU and the US that currently supports them. But Keppeler’s warning from early 2025 that you have to “watch for the tipping point” has only gained weight since: after a US Supreme Court decision in June 2026, the European data-protection authorities officially asked the EU Commission to review the agreement. Nothing has been struck down. But the foundation is visibly shaking.

For your provider selection, this calls not for panic but for two sober questions: where exactly is the call data processed — not the company’s headquarters, but the servers? And is there a data processing agreement that cleanly settles responsibilities? A reputable provider answers both without hesitation.

AI phone assistants in medical practices and law firms: Confidentiality under Section 203 of the German Criminal Code

One group has to look more closely than everyone else: professionals bound to confidentiality. Doctors, dentists, lawyers, notaries, tax advisors, pharmacists — for them, on top of GDPR, there’s the criminally enforceable duty of confidentiality under Section 203 of the German Criminal Code. It’s far older than any AI debate, and it does not mess around.

Medical practices in particular like to reach for a phone appointment assistant, because that’s where the bottleneck is biggest. That’s understandable, and it’s also doable. But here Keppeler makes his most emphatic statement in the whole conversation:

“So I should be extremely careful here — this is where I would not want to be pragmatic.” (22:31)

The reason: even the information that someone is a patient of a particular practice can be a protected secret. If such data flows unexamined through an AI system — possibly one that reuses inputs for training — the accusation of disclosing confidential information quickly enters the room. The law does have an exception for contractually bound service providers. I wouldn’t rely on that alone.

The practical takeaway from the interview: in a practice or law firm, caller consent belongs in the setup, and the provider questions above apply doubly here. Once set up properly, this stops being an ongoing issue — but it belongs in the initial setup, not in later patching.

AI officers and AI training obligations: Where the all-clear is warranted

The video title says it already: Keppeler doesn’t think much of the “AI officer.” And this passage may be the most valuable in the whole interview, because here a lawyer argues against the business model of many consultants.

Yes, the EU AI Act requires that employees be trained in handling AI. But: the scope depends on what people actually do with AI. Someone who occasionally has copy drafted needs a short briefing on the standard risks — not a certified degree. There is no standalone fine for violating the training obligation. The expensive “AI officer” certificates currently being marketed are required by the law nowhere.

Keppeler’s framing is disarmingly honest: the consultants make “more fuss about it than the EU legislators ever intended.” His tell for dubious offers: anyone who threatens you with horror scenarios and in the same breath sells you a compliance package — get a second quote. You recognize credibility by demonstrable experience and by certificates backed by a real examination — not by five AI-guru badges in an email signature.

You’re welcome to hold me to that same standard, by the way.

Checklist: The questions to ask your provider before launch

From the interview and the current legal situation, a compact checklist emerges. You don’t have to work out the answers yourself — you just have to ask the questions and insist on clear answers.

Question for the providerWhat to look for
Does the assistant identify itself as an AI?Mandatory since August 2, 2026 — the disclosure belongs in the greeting, not the fine print
Where is the call data processed?Server location and services involved, not just the company headquarters
Is there a data processing agreement?Must be in place before the first real call
Are conversations reused for AI training?Should be excluded or possible to switch off — for practices and law firms, non-negotiable
Is a privacy-policy template included?A provider who thought of this has usually thought of the rest too
For a practice or law firm: how is consent handled?Anyone who waves this off doesn’t know Section 203 — walk away

A note on my own behalf: I verified the details from the video before writing this post. The Munich Google Fonts ruling awarded €100; the conversation casually mentioned €50 — it doesn’t change the story. The statements on authority jurisdiction and the AI Act timeline were accurate as of early 2025 and have since been confirmed — or overtaken — by reality, as described above.

My take

The interview is a year and a half old, and that’s exactly what makes it worth reading: almost everything the attorney cautiously predicted back then has come to pass. The labeling obligation is in force, the oversight body is in place, the path to damages has been paved. Anyone deploying an AI phone assistant today is no longer moving in a gray area — the rules are known, and they are meetable. The effort is manageable: a disclosure in the greeting, a proper contract, clarified data flows. That’s not a project — that’s diligence at setup.

What bothers me about the debate is something else. In many minds, “there are rules” turns into “it’s too risky.” And that’s the most expensive wrong decision of all.

My assessment: All this legislation and the talk of cease-and-desist waves scares many companies so much that they never even try things — and that smothers a lot before it starts. I fully agree with Keppeler’s line that you have to stay pragmatic: comply with the legal requirements, of course, but don’t let yourself be so deterred that you stop doing anything, because otherwise you fall behind. In Europe, that’s unfortunately harder than elsewhere. But you can’t let yourself be intimidated into doing nothing at all with AI.

If you’re planning a phone assistant and want to know where your business stands legally: ask the six questions from the checklist — of your provider, or gladly of me. The answers take a conversation, not a legal opinion.