The AI Act also applies to your CRM system. Do you have it under control?

August 28, 2026
Ole Aavik
CRM
Artikkel

On August 2, 2026, most of the obligations under the EU AI Act came into effect, including the new transparency requirements. If your business uses a modern CRM platform, there is a good chance that AI is already running within your system: lead scoring, forecasting, chat agents, and content generation.

But do you know what the regulations actually require of you? Not as purchasers of the technology, but as users of it.

Many leadership teams treat the AI Act as something that only affects tech companies developing AI. That is a misunderstanding that could prove costly.

What happened on August 2?

The AI Act is the world's first comprehensive AI regulation, and it is risk-based: the greater the risk the AI usage poses to individuals and society, the stricter the requirements.

The regulation has entered into force gradually:

February 2025: A ban on the most intrusive AI practices, and a requirement that everyone using AI must possess sufficient competence (so-called AI literacy).

August 2025: Requirements for generative AI models, i.e., the foundation models behind chatbots and assistants.

August 2, 2026: Most of the remaining obligations, including transparency requirements that customers must know when they are speaking to a chatbot, and the labeling of AI-generated content. The EU's simplification package (AI Omnibus), which entered into force on July 27, 2026, postponed the strictest requirements for high-risk AI systems until December 2, 2027.

The regulations apply in the EU and are incorporated into Norway via the EEA Agreement with national adaptations. If your business operates in the internal market or has customers in the EU, the requirements already affect you regardless.

Your CRM system is likely already using AI

You don't need to have "bought AI" to use AI. Modern CRM platforms come with AI features built into the standard product:

  • Lead scoring and prioritization that automatically ranks contacts and deals
  • Predictive forecasting for pipeline and revenue
  • Chat agents and chatbots that respond to customers via web and email
  • Content generation for emails, campaigns, and landing pages
  • Data enrichment that automatically populates fields about contacts and companies

In addition, there is shadow AI: employees pasting customer data into ChatGPT or similar tools to write emails and summarize meetings.

Most businesses are therefore already AI users. And that is precisely the role to which the regulations attach obligations.

The rules apply to those who use the systems

Many believe the AI Act only regulates the providers. In reality, the regulation distinguishes between providers, who develop AI systems, and users, who implement them in their own operations.

A Norwegian business using a CRM platform with AI features is typically a user. And users have independent obligations:

  1. Use the system as intended and follow the provider's instructions.
  2. Ensure human oversight of significant decisions influenced by AI.
  3. Ensure data quality for data fed into the system.
  4. Inform and be transparent when humans interact with AI.
  5. Ensure that employees have sufficient AI competence. This requirement has already been in effect since February 2025.

What the regulations specifically require of you

The applicable obligations depend on the risk category. Most CRM-related AI falls into the limited risk category, but there are exceptions.

  • Transparency: Customers must know they are speaking to a chatbot. AI-generated content must be labeled. If you have a web support agent that responds automatically, this applies to you.
  • AI competence: Organizations must be able to document that employees who use or manage AI understand what the systems do and what their limitations are. For many businesses, this is the most urgent obligation: Plan training, and document it.
  • High-risk use: Some forms of AI use trigger stricter requirements: automated credit scoring, risk and pricing assessments in life and health insurance, the allocation of essential public services, or AI used in recruitment. If your industry uses AI to assess individuals' rights or access to services, you should carefully consider whether you fall into the high-risk category. If so, stricter requirements for documentation, logging, risk assessments, and human oversight will apply from December 2, 2027.
  • GDPR still applies: The AI Act does not replace data protection regulations; it complements them. Automated decisions about individuals are still regulated by the GDPR, and the AI Act's data quality requirements assume that you have control over your data foundation regardless.
  • Sanctions: Violations can cost up to 35 million euros or 7 percent of global turnover for the most serious breaches, and up to 15 million euros or 3 percent for other violations.

The smartest answer is not a legal assessment

Here, we take the liberty of challenging the reflex to send this to the legal department and wait for a report.

The requirements in the AI Act—data quality, documentation, human oversight, access control, and logging—are not primarily legal exercises. They are operational. And they overlap almost entirely with what you need anyway to get value out of AI.

Consider this:

  • AI that scores leads at the top of a CRM full of duplicates and outdated fields produces a basis for decision-making that you cannot trust. In that case, the data quality requirement hits you twice: once in the regulations, and once in your results.
  • A chat agent that answers customers using incorrect or outdated knowledge damages your brand. In that case, human oversight becomes a quality requirement, not just a compliance requirement.
  • Employees who paste customer data into random AI tools create risks you cannot even see. In that case, the competence requirement is your most concrete protection.

There is, therefore, a direct link between compliance and value creation: Businesses that have control over their CRM data and processes become both regulatory-compliant and better at utilizing the AI they are already paying for.

Five things you should do now

  1. Take stock of your AI usage. Map out where AI is currently being used: within your CRM platform, in other systems, and through employees' use of external tools.
  2. Classify the risk of each use case. Distinguish between limited risk and potential high-risk usage. Start where AI directly impacts customers.
  3. Establish an AI policy. Clear guidelines on what is permitted, what data can be used, and who is responsible.
  4. Train your employees. The need for competence is already here. Document all training.
  5. Clean up your data foundation. Data quality, access control, and logging are prerequisites for both compliant and valuable AI.

How Axaz can help you

Axaz CRM offers a review that gives you control quickly:

CRM Audit is a structured review of your entire CRM setup: data quality, adoption rates, integrations, security, and GDPR compliance, including a concrete assessment of where AI can replace manual steps today.

Wondering where your business stands? Book a no-obligation CRM coffee chat with us, and we will give you an honest assessment of your starting point.

This article is for awareness purposes and does not constitute legal advice. Its content is intended to make leaders aware of the practical implications of the AI Act and does not replace professional legal counsel. For specific legal assessments, you should consult with a lawyer.

How we work with

CRM

 at Axaz?

Employees at Axaz
Many organizations find that their CRM system becomes a burden instead of a tool for growth. Data is in silos, processes are fragmented, and users lose motivation. Axaz helps companies build data-driven, scalable, and customer-oriented processes in HubSpot - powered by AI and anchored in business goals. With our combination of CRM expertise, technological understanding, and experience from complex organizations, we ensure that the CRM is actually used - and creates value from day one.
Read more

You might be interested in...

View more on our blog